Open Access Management Vulnerability in OpenAM Affects Client Authentication Process
CVE-2026-47426
7.6HIGH
What is CVE-2026-47426?
Open Access Management (OpenAM) is an access management solution that has a vulnerability in its client authentication path. Prior to version 16.1.1, the process utilizes a ClientJwksResolverCache without ensuring that a cached jwks_uri resolver or verified assertion corresponds correctly to the intended clientID. This flaw allows an attacker with control over a registered client—potentially created through open dynamic registration—to authenticate as a different client. This enables the attacker to mint tokens in the name of the targeted client, posing significant security risks across various realms within the same OpenAM instance. Users are strongly advised to upgrade to version 16.1.1 or later to mitigate this issue.
Affected Version(s)
OpenAM < 16.1.1
