Description
OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding delegated RealmAdmin privileges can supply a _queryFilter naming another realm to disclose usernames, universal IDs, and session handles across tenant boundaries.
Published: 2026-10-03
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Cross-Realm Session Disclosure
Action: Patch Now
AI Analysis

Impact

OpenAM versions before 16.1.3 contain an authorization bypass in the sessions REST endpoint that lets a user with RealmAdmin privileges query the sessions of any realm. The flaw allows disclosure of usernames, universal IDs, and session handles spanning across tenant boundaries. This information breach compromises confidentiality and could enable further session hijacking or credential misuse. The weakness is an authorization flaw classified as CWE-200.

Affected Systems

Vendors and products affected are the OpenIdentityPlatform OpenAM solutions prior to version 16.1.3. Any installation of OpenAM running an earlier major release that exposes the sessions REST API is potentially vulnerable. The vulnerability applies to the default REST endpoint in these releases.

Risk and Exploitability

The CVSS score is 6.9, indicating a moderate severity. EPSS score is currently unavailable, so the likelihood of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to possess delegated RealmAdmin privileges and to access the REST API over the network, which is typically provided via HTTPS. The attacker can inject a _queryFilter with a target realm name to retrieve session data from other realms.

Generated by OpenCVE AI on October 3, 2026 at 15:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenAM to version 16.1.3 or later to receive the fix.
  • Limit delegated RealmAdmin permissions to only trusted administrators and review role assignments.
  • Apply network segmentation or firewall controls to restrict access to the OpenAM sessions REST endpoint from untrusted networks.

Generated by OpenCVE AI on October 3, 2026 at 15:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding delegated RealmAdmin privileges can supply a _queryFilter naming another realm to disclose usernames, universal IDs, and session handles across tenant boundaries.
Title OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpoint
First Time appeared Openidentityplatform
Openidentityplatform openam
Weaknesses CWE-200
CPEs cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*
Vendors & Products Openidentityplatform
Openidentityplatform openam
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-03T12:14:44.244Z

Reserved: 2026-10-03T12:04:36.964Z

Link: CVE-2026-105120

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T14:16:38.853

Modified: 2026-10-03T14:16:38.853

Link: CVE-2026-105120

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T15:30:19Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor