Skip to content
Threat Feed

Vendor

Open Identity Platform

3 briefs RSS
high advisory

Insecure SSO Cookie Configuration in OpenAM

OpenAM Community Edition versions prior to 16.1.1 are vulnerable to session theft and unauthorized OAuth consent grants due to insecure SSO cookie initialization (CVE-2026-53660).

OpenAM Community Edition
critical advisory

OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI (CVE-2026-46495)

A critical pre-authentication remote code execution (RCE) vulnerability, CVE-2026-46495, exists in OpenDJ Community Edition affecting versions up to 5.1.0, where a deserialization of untrusted data issue in the JMX RMI connector allows unauthenticated attackers with TCP reachability to the JMX listener to execute arbitrary Java objects, potentially leading to full system compromise.

OpenDJ Community Edition <= 5.1.0 +1 java deserialization rce opendj jmx-rmi pre-auth network
2t
critical advisory

OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints (CVE-2026-45052)

An improper authorization vulnerability (CVE-2026-45052) in OpenAM Community Edition through version 16.0.6 allows an unauthenticated attacker to write persistent entries into the Liberty Discovery store on any user's LDAP entry and a shared root-realm Discovery branch, due to a flaw in the Liberty Web Services SOAP receiver that permits anonymous writes with elevated internal privileges, potentially influencing service routing or security mechanisms if Liberty discovery data is consumed.

OpenAM Community Edition +1 vulnerability identity-management web-application openam
2t