{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/openam-auth-webauthn/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["openam-auth-webauthn"],"_cs_severities":["critical"],"_cs_tags":["deserialization","rce","webauthn","java","openam","vulnerability"],"_cs_type":"advisory","_cs_vendors":["OpenIdentityPlatform"],"content_html":"\u003cp\u003eA critical deserialization vulnerability, tracked as CVE-2026-62263, has been identified in the \u003ccode\u003eopenam-auth-webauthn\u003c/code\u003e component of OpenAM (Open Identity Platform). This flaw affects versions up to and including 16.1.1. The vulnerability stems from an insufficient fix (GHSA-6c99-87fr-6q7r) that attempted to secure WebAuthn authenticator deserialization using an \u003ccode\u003eObjectInputFilter\u003c/code\u003e. However, the filter is inadvertently bypassed for any object at a stream depth greater than one, effectively constraining only the root object and leaving nested serialized objects unchecked. This design flaw allows an unauthenticated attacker to craft a specially designed serialized stream containing arbitrary Java gadget chains. When processed by OpenAM, this stream can trigger remote code execution (RCE) before any authentication takes place, posing a severe risk to affected deployments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker prepares a malicious serialized Java object stream.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts the root of this stream to be an \u003ccode\u003eAuthenticatorImpl\u003c/code\u003e object.\u003c/li\u003e\n\u003cli\u003eNested within the \u003ccode\u003eAuthenticatorImpl\u003c/code\u003e object, the attacker embeds a malicious gadget chain.\u003c/li\u003e\n\u003cli\u003eThe attacker sends this crafted serialized stream to the OpenAM server via an attacker-chosen \u003ccode\u003euserHandle\u003c/code\u003e, targeting the WebAuthn deserialization sink.\u003c/li\u003e\n\u003cli\u003eOpenAM attempts to deserialize the incoming WebAuthn authenticator data.\u003c/li\u003e\n\u003cli\u003eDuring deserialization, the \u003ccode\u003eObjectInputFilter\u003c/code\u003e is consulted but mistakenly short-circuits to \u003ccode\u003eALLOWED\u003c/code\u003e for objects at a stream depth greater than one.\u003c/li\u003e\n\u003cli\u003eThe embedded gadget chain's \u003ccode\u003ereadObject()\u003c/code\u003e or \u003ccode\u003ereadResolve()\u003c/code\u003e methods are invoked, leading to the execution of arbitrary code on the server.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves unauthenticated remote code execution on the OpenAM server, gaining control of the system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-62263 grants unauthenticated remote code execution (RCE) on the OpenAM server. This allows attackers to completely compromise the integrity, confidentiality, and availability of the affected system. Attackers could install backdoors, exfiltrate sensitive user authentication data, disrupt identity services, or pivot to other systems within the compromised network. The vulnerability affects \u003ccode\u003emaven/org.openidentityplatform.openam:openam-auth-webauthn\u003c/code\u003e in all versions up to and including 16.1.1, making a wide range of OpenAM deployments susceptible to this critical flaw.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-62263 by upgrading \u003ccode\u003emaven/org.openidentityplatform.openam:openam-auth-webauthn\u003c/code\u003e to a version greater than 16.1.1 immediately.\u003c/li\u003e\n\u003cli\u003eReview web server logs for the OpenAM application for suspicious requests that involve unusually large or malformed \u003ccode\u003euserHandle\u003c/code\u003e parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T21:10:01Z","date_published":"2026-07-24T21:10:01Z","id":"https://feed.craftedsignal.io/briefs/2026-07-openam-webauthn-deserialization-rce/","summary":"A critical remote code execution (RCE) vulnerability, CVE-2026-62263, exists in OpenAM's WebAuthn authenticator deserialization, allowing an unauthenticated attacker to bypass an `ObjectInputFilter` and execute arbitrary code by crafting a malicious serialized stream before authentication.","title":"Critical Unauthenticated Remote Code Execution in OpenAM WebAuthn due to Deserialization Vulnerability (CVE-2026-62263)","url":"https://feed.craftedsignal.io/briefs/2026-07-openam-webauthn-deserialization-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Openam-Auth-Webauthn","version":"https://jsonfeed.org/version/1.1"}