Access Management Solution Vulnerability in OpenAM by OpenIdentity
CVE-2026-48717
9.1CRITICAL
What is CVE-2026-48717?
OpenAM, an access management solution, has a vulnerability in its AuthorizationCodeGrantTypeHandler. Prior to version 16.1.1, the system does not require a code_verifier unless the realm-wide codeVerifierEnforced setting is enabled, which is disabled by default. This allows an attacker to intercept a PKCE-protected authorization code and redeem it without a proper code_verifier, leading to unauthorized access. Although public clients are directly affected, confidential-client exploitation could also occur, requiring additional client authentication materials. The issue was resolved in version 16.1.1.
Affected Version(s)
OpenAM < 16.1.1
