Description
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote requests to write persistent entries through SOAPReceiver and DiscoveryService into a user's Liberty Discovery store and the shared root-realm Discovery branch. The server-side handlers bypass requester LDAP and identity ACLs, and the global path uses an internal administrative token. Deployments that consume Liberty discovery data can subsequently use manipulated service-routing or security-mechanism records. This issue is fixed in version 16.1.1.
Published: 2026-09-15
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote privilege escalation and data tampering
Action: Immediate patch
AI Analysis

Impact

A user is affected by an unauthenticated remote vulnerability in OpenAM's Liberty Web Services SOAP receiver before version 16.1.1. The SOAPReceiver and DiscoveryService endpoints allow a remote attacker to issue SOAP requests that write arbitrary persistent entries into both a user’s Liberty Discovery store and the shared root‑realm Discovery branch. Server‑side handlers bypass LDAP and identity ACL checks and rely on an internal administrative token, enabling the attacker to create or modify service‑routing or security‑mechanism records for any user. This manipulation can alter user profiles, service configuration denial of service. This vulnerability is an Improper Authorization flaw (CWE‑285).

Affected Systems

OpenIdentityPlatform OpenAM (prior to version 16.1.1). All deployments consuming Liberty discovery data that expose the SOAPReceiver and DiscoveryService endpoints are vulnerable until the upgrade to 16.1.1 or later, where the issue is fixed.

Risk and Exploitability

The CVSS score of 9.3 marks it as a critical vulnerability with a high potential for attack, while an EPSS score of less than 1% indicates a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it via anonymous remote SOAP requests without authentication, making it accessible to anyone with network reach to the endpoints.

Generated by OpenCVE AI on September 17, 2026 at 18:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenIdentityPlatform OpenAM to version 16.1.1 or later to apply the fixed code
  • If an upgrade is not immediately possible, restrict or disable external access to the SOAPReceiver and DiscoveryService endpoints using firewall or network segmentation
  • Ensure that only authenticated and authorized requests can reach the SOAP interfaces by securing the endpoints with proper ACLs and token validation

Generated by OpenCVE AI on September 17, 2026 at 18:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-p462-xxwx-pqf4 OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints
History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Openidentityplatform
Openidentityplatform openam
Vendors & Products Openidentityplatform
Openidentityplatform openam

Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote requests to write persistent entries through SOAPReceiver and DiscoveryService into a user's Liberty Discovery store and the shared root-realm Discovery branch. The server-side handlers bypass requester LDAP and identity ACLs, and the global path uses an internal administrative token. Deployments that consume Liberty discovery data can subsequently use manipulated service-routing or security-mechanism records. This issue is fixed in version 16.1.1.
Title OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints
Weaknesses CWE-285
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:L/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T18:05:10.255Z

Reserved: 2026-05-08T18:07:27.342Z

Link: CVE-2026-45052

cve-icon Vulnrichment

Updated: 2026-09-16T17:49:54.521Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T10:17:04.307

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-45052

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses