Deserialization Vulnerability in OpenAM Access Management Solution
CVE-2026-62263

9.2CRITICAL

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-62263?

The OpenAM access management solution is vulnerable to a deserialization issue in its WebAuthnAuthentication component prior to version 16.1.2. An attacker can exploit this vulnerability by supplying a userHandle with a serialized graph containing a valid AuthenticatorImpl root object, along with a nested gadget class. This process can trigger a readObject or readResolve execution before proper casting and assertion verification, potentially leading to an exploitation of the system. Users are advised to update to version 16.1.2 or later to mitigate this risk. For more details, refer to the official advisory and fix notes.

Affected Version(s)

OpenAM < 16.1.2

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.