Access Management Vulnerability in OpenAM by OpenIdentityPlatform
CVE-2026-62280

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-62280?

OpenAM, developed by OpenIdentityPlatform, has a vulnerability in its OAuth2 authorization process between versions 13.0.0 and 16.1.2. This issue arises from the failure to properly escape request-derived values in the consent page displayed through the OAuth2 authorize endpoint. By exploiting this flaw, an attacker can manipulate a user's active session with OpenAM. When the user clicks on a specially crafted authorization link, the attack can execute malicious JavaScript within the OpenAM origin environment. This can lead to severe security breaches, including session hijacking, unauthorized access to cookies, and CSRF-token disclosure. It is important to upgrade to version 16.1.2 or later to mitigate this vulnerability.

Affected Version(s)

OpenAM >= 13.0.0, < 16.1.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.