Server-Side Scripting Vulnerability in Open Access Management by OpenIdentityPlatform
CVE-2026-47424

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-47424?

The Open Access Management (OpenAM) solution by OpenIdentityPlatform contains a significant server-side scripting vulnerability that affects versions prior to 16.1.1. This flaw allows authenticated server-side script authors, such as sub-realm RealmAdmins, to bypass the scripting sandbox restrictions. Consequently, they can execute operating system commands as the OpenAM application server account, breaching administrative boundaries and potentially compromising the Java Virtual Machine (JVM) and all realms under its management. The issue has been addressed in version 16.1.1, which users are urged to upgrade to for enhanced security.

Affected Version(s)

OpenAM < 16.1.1

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.