Access Management Solution Vulnerability in OpenAM by OpenIdentityPlatform
CVE-2026-53660

7.4HIGH

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-53660?

A vulnerability in OpenAM, an access management solution, results from improper initialization of the iPlanetDirectoryPro SSO cookie prior to version 16.1.1. The default configuration permits the cookie to be accessed without HttpOnly protection and lacks a suitable SameSite attribute. Additionally, OAuth and OpenID Connect consent flows rely on this cookie as a CSRF token, making it susceptible to exploitation. When a victim follows an attacker-controlled link, the compromised cookie can be read, allowing an attacker to hijack the SSO session and obtain unauthorized consent grants. This vulnerability has been addressed in version 16.1.1.

Affected Version(s)

OpenAM < 16.1.1

References

CVSS V4

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.