Access Management Solution Vulnerability in OpenAM by OpenIdentityPlatform
CVE-2026-53660
7.4HIGH
What is CVE-2026-53660?
A vulnerability in OpenAM, an access management solution, results from improper initialization of the iPlanetDirectoryPro SSO cookie prior to version 16.1.1. The default configuration permits the cookie to be accessed without HttpOnly protection and lacks a suitable SameSite attribute. Additionally, OAuth and OpenID Connect consent flows rely on this cookie as a CSRF token, making it susceptible to exploitation. When a victim follows an attacker-controlled link, the compromised cookie can be read, allowing an attacker to hijack the SSO session and obtain unauthorized consent grants. This vulnerability has been addressed in version 16.1.1.
Affected Version(s)
OpenAM < 16.1.1
