Description
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbitrary notification URL without requiring an administrative or application client token. SessionRequestHandler passes the attacker-controlled destination to the session listener service, causing the OpenAM server to make outbound requests and potentially disclose session-related notification data to an attacker-controlled destination. This issue is fixed in version 16.1.1.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery exposing session data
Action: Patch Now
AI Analysis

Impact

The vulnerability lies in the /sessionservice addSessionListener operation, which allows any authenticated user to register an arbitrary notification URL without requiring administrative or application client privileges. The OpenAM server then forwards the attacker‑controlled destination to the session listener service, causing outbound requests that can leak session‑related data to a Server‑Side Request Forgery (SSRF) and maps to CWE‑918. It does not lead to code execution but can expose sensitive information to external sites.

Affected Systems

This flaw affects any OpenIdentityPlatform OpenAM deployment running a version prior to 16.1.1. All installations of OpenAM 16.0.x and earlier that expose the /sessionservice endpoint to normal users are vulnerable. The fix was released in version 16.1.1 and later.

Risk and Exploitability

The CVSS score of 5.3 reflects moderate impact, while the EPSS score is less than 1 %, indicating a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. An attacker must first authenticate to OpenAM and then invoke the addSessionListener endpoint with a malicious URL. The server will make an outbound request to that URL, potentially leaking session data to the attacker’s controlled destination. No elevated privileges are required, so any authenticated user with access to the endpoint can exploit the flaw.

Generated by OpenCVE AI on September 17, 2026 at 18:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to OpenAM 16.1.1 or newer to apply the official fix.
  • Restrict the OpenAM ports to limit potential SSRF impact.
  • Enforce that only administrative or application client accounts can call the addSessionListener endpoint by reviewing configuration and access controls, ensuring normal users cannot register arbitrary URLs.

Generated by OpenCVE AI on September 17, 2026 at 18:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-c556-q2mh-477v OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice`
History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Openidentityplatform
Openidentityplatform openam
Vendors & Products Openidentityplatform
Openidentityplatform openam

Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbitrary notification URL without requiring an administrative or application client token. SessionRequestHandler passes the attacker-controlled destination to the session listener service, causing the OpenAM server to make outbound requests and potentially disclose session-related notification data to an attacker-controlled destination. This issue is fixed in version 16.1.1.
Title OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice`
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T14:22:13.301Z

Reserved: 2026-05-05T15:13:47.571Z

Link: CVE-2026-44202

cve-icon Vulnrichment

Updated: 2026-09-15T14:22:10.253Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T10:17:03.350

Modified: 2026-09-25T14:23:59.847

Link: CVE-2026-44202

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)