Description
OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.
Published: 2026-10-03
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Improper Authorization allowing hostile session termination across realms
Action: Apply patch
AI Analysis

Impact

The flaw is an improper authorization vulnerability in the session-destroy endpoint of OpenAM. Delegated administrators that possess the iplanet-am-session-destroy-sessions attribute can supply a session identifier or handle and forcefully log out any user, regardless of the realm that owns the session. This capability enables the attacker to disrupt service availability and undermine accountability across all realms. The weakness is classified as CWE‑285.

Affected Systems

Products from OpenIdentityPlatform, specifically OpenAM versions prior to 16.1.3, are affected. Those installations perform realm checks using the requester's realm instead of the target session’s realm, which allows the described privilege escalation.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity. With the EPSS score not available and no listing in the CISA KEV catalog, the likelihood of widespread exploitation appears moderate to low; however, the ability to terminate arbitrary sessions could be leveraged in targeted assaults. The attack vector is inferred to be remote via the network: an attacker first authenticates as a delegated admin with the required attribute, then submits a request to the session-destroy endpoint to exploit the flaw.

Generated by OpenCVE AI on October 3, 2026 at 15:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to OpenAM 16.1.3 or later, which contains the vendor fix.
  • Revoke the iplanet-am-session-destroy-sessions attribute from delegated administrator accounts or restrict it to a minimal trusted set.
  • Disable or tightly control the session-destroy API for high‑privileged users and implement monitoring of its usage.

Generated by OpenCVE AI on October 3, 2026 at 15:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.
Title OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping
First Time appeared Openidentityplatform
Openidentityplatform openam
Weaknesses CWE-285
CPEs cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*
Vendors & Products Openidentityplatform
Openidentityplatform openam
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-03T12:14:44.905Z

Reserved: 2026-10-03T12:04:36.964Z

Link: CVE-2026-105121

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T14:16:38.997

Modified: 2026-10-03T14:16:38.997

Link: CVE-2026-105121

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T15:30:19Z

Weaknesses