Deserialization Vulnerability in OpenAM Access Management Solution
CVE-2026-62263
9.2CRITICAL
What is CVE-2026-62263?
The OpenAM access management solution is vulnerable to a deserialization issue in its WebAuthnAuthentication component prior to version 16.1.2. An attacker can exploit this vulnerability by supplying a userHandle with a serialized graph containing a valid AuthenticatorImpl root object, along with a nested gadget class. This process can trigger a readObject or readResolve execution before proper casting and assertion verification, potentially leading to an exploitation of the system. Users are advised to update to version 16.1.2 or later to mitigate this risk. For more details, refer to the official advisory and fix notes.
Affected Version(s)
OpenAM < 16.1.2
