Description
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() passes the _queryId parameter from /json/{realm}/users to CrestQuery with escapeQueryId disabled, bypassing protection added for CVE-2021-29156. The unescaped value reaches DJLDAPv3Repo.getFilter(), where it is concatenated into an LDAP filter, allowing an authenticated attacker to inject LDAP metacharacters for user enumeration and blind LDAP injection. This issue is fixed in version 16.1.1.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: LDAP Injection
Action: Patch Immediately
AI Analysis

Impact

OpenAM users exposed the possibility for an attacker with valid authentication to inject LDAP metacharacters by exploiting the unescaped _queryId parameter in the /json/{realm}/users endpoint. Prior to version 16.1.1, the IdentityResourceV1.queryCollection() method forwarded this value to CrestQuery with escapeQueryId disabled, bypassing earlier defenses for CVE-2021-29156. The unescaped value reached DJLDAPv3Repo.getFilter(), where it was concatenated into an LDAP filter, allowing user enumeration and blind LDAP injection. This flaw was identified as CWE‑90 and carries a CVSS score of 7.1, indicating a high severity impact on data confidentiality and potential privilege escalation.

Affected Systems

All OpenIdentityPlatform OpenAM installations running any version before 16.1.1 are affected. The fix is implemented in OpenAM release 16.1.1 and later versions.

Risk and Exploitability

The risk is high but the probability of exploitation remains low, with an EPSS score of less than 1%. The CVSS score of 7.1 reflects a high severity. Not listed in the CISA KEV catalog. Attacks would require authenticated access to the affected endpoint and the ability to manipulate the _queryId parameter, so the threat is primarily to authenticated users who can enumerate credentials or perform further LDAP queries.

Generated by OpenCVE AI on September 17, 2026 at 17:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenAM to version 16.1.1 or later, which removes the unchecked _queryId handling.
  • Restrict or disable the /json/{realm}/users API for unauthenticated requests and limit its use for authenticated users through ACL changes.
  • Apply input sanitization or escape functions to the _queryId parameter to prevent LDAP metacharacter injection until the patch is applied.

Generated by OpenCVE AI on September 17, 2026 at 17:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2vg8-q4c2-5cw3 OpenAM has LDAP Injection via `_queryId` Parameter
History

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Openidentityplatform
Openidentityplatform openam
Vendors & Products Openidentityplatform
Openidentityplatform openam

Tue, 15 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Description Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() passes the _queryId parameter from /json/{realm}/users to CrestQuery with escapeQueryId disabled, bypassing protection added for CVE-2021-29156. The unescaped value reaches DJLDAPv3Repo.getFilter(), where it is concatenated into an LDAP filter, allowing an authenticated attacker to inject LDAP metacharacters for user enumeration and blind LDAP injection. This issue is fixed in version 16.1.1.
Title OpenAM LDAP Injection via `_queryId` Parameter
Weaknesses CWE-90
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T12:41:34.659Z

Reserved: 2026-04-21T14:15:21.957Z

Link: CVE-2026-41573

cve-icon Vulnrichment

Updated: 2026-09-15T12:41:17.979Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T10:17:03.123

Modified: 2026-09-23T18:21:42.327

Link: CVE-2026-41573

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-90

    Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')