{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/openam--16.1.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenAM \u003c= 16.1.1"],"_cs_severities":["critical"],"_cs_tags":["openam","rce","java","authentication","webserver"],"_cs_type":"advisory","_cs_vendors":["OpenAM"],"content_html":"\u003cp\u003eA critical pre-authentication remote code execution (RCE) vulnerability, identified as CVE-2026-62379, exists in OpenAM releases up to and including version 16.1.1. This flaw allows an unauthenticated attacker to execute arbitrary code on the server due to improper validation in the remote authentication endpoint, \u003ccode\u003e/authservice\u003c/code\u003e. The vulnerability stems from the \u003ccode\u003eAuthXMLUtils.createCustomCallback\u003c/code\u003e function, which accepts an XML element naming an arbitrary Java class. The OpenAM server then loads and instantiates this class without proper security checks, leading to unauthenticated code execution. This puts any OpenAM instance with default settings at severe risk of complete server compromise, making it a high-priority concern for defenders.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker sends a specially crafted HTTP POST request to the \u003ccode\u003e/authservice\u003c/code\u003e endpoint of a vulnerable OpenAM server.\u003c/li\u003e\n\u003cli\u003eThe POST request includes an XML payload containing an element that specifies an arbitrary Java class name (e.g., \u003ccode\u003ejava.lang.Runtime\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe OpenAM server, upon receiving the request, processes the XML payload.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eAuthXMLUtils.createCustomCallback\u003c/code\u003e method is invoked, attempting to load the attacker-specified Java class using \u003ccode\u003eClass.forName\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe server instantiates the arbitrary class without validating its legitimacy or origin.\u003c/li\u003e\n\u003cli\u003eThe malicious code embedded within the attacker-controlled Java class executes on the OpenAM server with the privileges of the application.\u003c/li\u003e\n\u003cli\u003eThe attacker gains remote code execution capabilities on the server, allowing for full system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-62379 results in unauthenticated remote code execution (RCE) and full server compromise on any OpenAM instance running default configurations up to version 16.1.1. This allows an attacker to gain complete control over the affected server, leading to data theft, service disruption, and potentially further network penetration. The vulnerability's pre-authentication nature means that an attacker does not need any prior access or credentials to initiate the attack, making it extremely dangerous. The specific number of victims and targeted sectors are not detailed, but all organizations using the affected OpenAM versions are at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all OpenAM instances to version \u003ccode\u003e16.1.2\u003c/code\u003e immediately to remediate CVE-2026-62379.\u003c/li\u003e\n\u003cli\u003eAs an interim mitigation, enable \u003ccode\u003esunRemoteAuthSecurityEnabled\u003c/code\u003e to require a remote-auth security token, which will reject unauthenticated calls to \u003ccode\u003e/authservice\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eRestrict or block external network access to the \u003ccode\u003e/authservice\u003c/code\u003e endpoint until systems are patched or the mitigation is in place.\u003c/li\u003e\n\u003cli\u003eDeploy the webserver detection rule to identify attempts to access the \u003ccode\u003e/authservice\u003c/code\u003e endpoint, though more specific detection may require application-layer logging for XML body content.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T21:12:26Z","date_published":"2026-07-24T21:12:26Z","id":"https://feed.craftedsignal.io/briefs/2026-07-openam-rce/","summary":"An unauthenticated remote code execution vulnerability, tracked as CVE-2026-62379, affects OpenAM up to and including version 16.1.1, allowing attackers to achieve full server compromise by sending a crafted XML element to the `/authservice` endpoint that names and instantiates an arbitrary Java class without validation on default configurations.","title":"OpenAM Unauthenticated Remote Code Execution Vulnerability via Class.forName","url":"https://feed.craftedsignal.io/briefs/2026-07-openam-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenAM \u003c= 16.1.1","version":"https://jsonfeed.org/version/1.1"}