Description
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators without an ObjectInputFilter. Exploitation requires the WebAuthn flow to be reachable and an attacker to have previously written controlled data to that attribute through delegated administration, provisioning, directory access, legacy REST self-registration, or unsafe configuration. When those non-default conditions hold, the data is deserialized before assertion verification and can execute a classpath gadget in the application server process. This issue is fixed in version 16.1.1.
Published: 2026-09-15
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in OpenIdentityPlatform OpenAM versions prior to 16.1.1. During the WebAuthn authentication flow, the application deserializes a userAttribute object graph without applying an ObjectInputFilter. An attacker who has already written controlled data into that attribute—through delegated administration, provisioning, directory access, legacy REST self‑registration, unsafe configuration—can inject a malicious Java object that triggers classpath gadget execution before the assertion is verified. The result is arbitrary code execution with the privileges of the application server.

Affected Systems

Affected systems are instances of OpenIdentityPlatform OpenAM running any release older than 16.1.1. The vulnerability is tied to the WebAuthnAuthenticator component and impacts users who can supply data to the configured userAttribute. Administrators deploying1 should check whether their environment allows untrusted writes to that attribute.

Risk and Exploitability

The CVSS score of 9.2 classifies this as a critical flaw, though the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild, and it is not currently listed in the CISA KEV catalog. Nevertheless, exploitation requires the WebAuthn flow to be exposed and attacker control over the attribute, conditions that are uncommon but possible in misconfigured installations. Given the high severity, the risk remains significant if the prerequisite conditions exist.

Generated by OpenCVE AI on September 17, 2026 at 17:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenAM to version 16.1.1 or later to receive the fix that validates deserialization.
  • Restrict or disable delegated administration and other write access paths to the userAttribute used by WebAuthn to prevent attackers from injecting malicious objects.
  • If upgrading is not immediately possible, disable the WebAuthn authentication flow or isolate the component from untrusted input until a patch is applied.

Generated by OpenCVE AI on September 17, 2026 at 17:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-6c99-87fr-6q7r OpenAM: Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage
History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Openidentityplatform
Openidentityplatform openam
Vendors & Products Openidentityplatform
Openidentityplatform openam

Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators without an ObjectInputFilter. Exploitation requires the WebAuthn flow to be reachable and an attacker to have previously written controlled data to that attribute through delegated administration, provisioning, directory access, legacy REST self-registration, or unsafe configuration. When those non-default conditions hold, the data is deserialized before assertion verification and can execute a classpath gadget in the application server process. This issue is fixed in version 16.1.1.
Title OpenAM Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage
Weaknesses CWE-502
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T13:53:10.904Z

Reserved: 2026-05-08T18:07:27.342Z

Link: CVE-2026-45051

cve-icon Vulnrichment

Updated: 2026-09-15T13:26:15.960Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T10:17:04.153

Modified: 2026-09-23T18:21:42.327

Link: CVE-2026-45051

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data