Description
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not enforce ownership or privilege checks when a low-privileged authenticated user queries session information in deployments using stateful session storage. A requester who knows a target identity identifier can retrieve another user's active session credentials, including credentials for a more privileged account, and use them to hijack that session. This issue is fixed in version 16.1.1.
Published: 2026-09-15
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Session hijacking
Action: Apply patch
AI Analysis

Impact

An authenticated low‑privileged user can enumerate sessions belonging to other users by querying the SessionRequestHandler endpoint, because the handler does not check that the requester owns the queried session. The attacker may thereby obtain a session token for a higher‑privileged account and hijack that session, effectively gaining the privileges of the target account. This flaw corresponds to inadequate access control and disclosure of sensitive information, as identified by CWE‑200 and CWE‑285.

Affected Systems

OpenIdentityPlatform’s OpenAM product, any deployment using stateful session storage before version 16.1.1. The flaw is fixed in OpenAM 16.1.1.

Risk and Exploitability

The CVSS score of 8.5 classifies the vulnerability as high severity. The very low EPSS score (<1%) suggests that exploitation is considered unlikely at this time, and the vulnerability is not yet documented in the CISA KEV catalog. The attack requires that the adversary already has valid, low‑privileged credentials and can send requests to the session endpoint; once those conditions are met, the vulnerability can be leveraged to hijack a target user’s active session.

Generated by OpenCVE AI on September 16, 2026 at 05:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenAM to version 16.1.1 or later to apply the official fix.
  • If an immediate upgrade is impossible, reconfigure the application to disable direct session queries by low‑privileged roles or enforce ownership checks manually in custom code.
  • Monitor authentication logs for unusual session lookup activity and restrict the SessionRequestHandler API to privileged users when possible.

Generated by OpenCVE AI on September 16, 2026 at 05:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vvhj-w2jq-263q OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC
History

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Openidentityplatform
Openidentityplatform openam
Vendors & Products Openidentityplatform
Openidentityplatform openam

Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not enforce ownership or privilege checks when a low-privileged authenticated user queries session information in deployments using stateful session storage. A requester who knows a target identity identifier can retrieve another user's active session credentials, including credentials for a more privileged account, and use them to hijack that session. This issue is fixed in version 16.1.1.
Title OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC
Weaknesses CWE-200
CWE-285
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T14:03:36.527Z

Reserved: 2026-05-08T18:07:27.341Z

Link: CVE-2026-45048

cve-icon Vulnrichment

Updated: 2026-09-17T14:03:25.835Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T10:17:03.993

Modified: 2026-09-23T18:19:19.803

Link: CVE-2026-45048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T06:00:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-285

    Improper Authorization