Threat Advisory

OpenAM Flaw Lets Attackers Run Code Without Authentication

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical pre-authentication remote code execution vulnerability, assigned CVE-2026-62379 with a CVSS score of 9.8, affects OpenAM. The remote authentication endpoint accepts an XML element naming an arbitrary Java class that the server loads and instantiates without validation, allowing an attacker to run code on the server unauthenticated via the affected endpoint, leading to full server compromise on any OpenAM instance with default settings, specifically all releases up to and including 16.1.1. This flaw type is a CWE-94 and CWE-470 issue, where the attack vector is network-based and requires low privileges, no user interaction, and has a high severity impact on confidentiality, integrity, and availability.

RECOMMENDATION:

We recommend you to update OpenAM to version 16.1.2.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical pre-authentication remote code execution vulnerability, assigned CVE-2026-62379 with a CVSS score of 9.8, affects OpenAM. The remote authentication endpoint accepts an XML element naming an arbitrary Java class that the server loads and instantiates without validation, allowing an attacker to run code on the server unauthenticated via the affected endpoint, leading to full server compromise on any OpenAM instance with default settings, specifically all releases up to and including 16.1.1. This flaw type is a CWE-94 and CWE-470 issue, where the attack vector is network-based and requires low privileges, no user interaction, and has a high severity impact on confidentiality, integrity, and availability.

RECOMMENDATION:

We recommend you to update OpenAM to version 16.1.2.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu