Description
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS callback handled by SnsMessageResource falls back to a CTS predicate blob after a messageId expires from the in-memory dispatcher, treats top-level blob keys as Java class names for Class.forName, and deserializes attacker-controlled JSON through Jackson. A low-privileged user who starts Push Registration and obtains the messageId, shared secret, and challenge can wait for expiry, replace the persistent blob through anonymous callbacks, and trigger class loading and construction in the OpenAM JVM. The primitive can cause classpath-dependent process execution, file writes, or denial of service, although command execution was not confirmed on the tested stock classpath. This issue is fixed in version 16.1.1.
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an unsafe) in OpenAM’s anonymous Push Notification SNS callback prior to version 16.1.1. When a messageId expires, the callback falls back to a stored CTS predicate blob, treating top-level keys as Java class names and using Class.forName to load them, while deserializing attacker-controlled JSON with Jackson. A low-privileged user with access to a push registration can manipulate the callback after expiry to trigger arbitrary class loading and constructor execution in the OpenAM JVM. This flaw can lead to classpath-dependent process execution, file writes, or denial of service, although verified command execution was not documented on the default classpath. The issue is fixed in OpenAM 16.1.1.

Affected Systems

The affected product is OpenIdentityPlatform’s OpenAM. All releases prior to version 16.1.1 are vulnerable. Any OpenAM installation that has not applied the advisory release 16.1.1 is susceptible.

Risk and Exploitability

The CVSS score of 7.7 signals a high severity vulnerability, but the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The flaw is not yet listed in CISA’s KEV catalog. The likely attack vector is remote, exploiting the anonymous SNS callback. Successful exploitation would require the attacker to register a push notification, obtain a messageId, wait for expiration, and then send a crafted callback. If the OpenAM JVM’s class the attacker could achieve process execution, corrupt files, or crash the system.

Generated by OpenCVE AI on September 17, 2026 at 17:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the OpenAM installation to version which removes the unsafe deserialization logic.
  • Restrict or block unauthenticated access to the SNS callback endpoint using network ACLs or application-level filtering to prevent anonymous callbacks from reaching the vulnerable code path.
  • Disable push notification functionality or manually purge the CTS predicate blob if push notifications are not required, thereby eliminating the fallback deserialization mechanism.

Generated by OpenCVE AI on September 17, 2026 at 17:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pp89-732f-3g8q OpenAM has Unsafe Java Deserialization via SNS
History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Openidentityplatform
Openidentityplatform openam
Vendors & Products Openidentityplatform
Openidentityplatform openam

Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS callback handled by SnsMessageResource falls back to a CTS predicate blob after a messageId expires from the in-memory dispatcher, treats top-level blob keys as Java class names for Class.forName, and deserializes attacker-controlled JSON through Jackson. A low-privileged user who starts Push Registration and obtains the messageId, shared secret, and challenge can wait for expiry, replace the persistent blob through anonymous callbacks, and trigger class loading and construction in the OpenAM JVM. The primitive can cause classpath-dependent process execution, file writes, or denial of service, although command execution was not confirmed on the tested stock classpath. This issue is fixed in version 16.1.1.
Title OpenAM Unsafe Java Deserialization via SNS
Weaknesses CWE-502
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T18:13:20.802Z

Reserved: 2026-05-13T08:19:32.603Z

Link: CVE-2026-45794

cve-icon Vulnrichment

Updated: 2026-09-16T18:13:16.628Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T10:17:04.470

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-45794

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data