Open Access Management Vulnerability in OpenAM Affects Client Authentication Process
CVE-2026-47426

7.6HIGH

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-47426?

Open Access Management (OpenAM) is an access management solution that has a vulnerability in its client authentication path. Prior to version 16.1.1, the process utilizes a ClientJwksResolverCache without ensuring that a cached jwks_uri resolver or verified assertion corresponds correctly to the intended clientID. This flaw allows an attacker with control over a registered client—potentially created through open dynamic registration—to authenticate as a different client. This enables the attacker to mint tokens in the name of the targeted client, posing significant security risks across various realms within the same OpenAM instance. Users are strongly advised to upgrade to version 16.1.1 or later to mitigate this issue.

Affected Version(s)

OpenAM < 16.1.1

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.