Description
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied token identifiers from the shared Core Token Store (CTS) without an OAuth-only namespace, and OAuthAdapter accepts a row whose BLOB claims to contain an OAuth token without binding the trusted CTS type or verifying integrity. An attacker who can place controlled JSON in CTS under a known token identifier, such as through Push Registration followed by an anonymous SNS callback in an enabled realm, can mint OAuth bearer tokens and OpenID Connect ID tokens with chosen subject, client, realm, and scope. The flaw does not by itself create an OpenAM SSO session or grant console access. This issue is fixed in version 16.1.1.
Published: 2026-09-15
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary OAuth Token Minting
Action: Apply Patch
AI Analysis

Impact

Open Access Management (OpenAM) is an access management solution. Prior to version 16.1.1, the OAuthTokenStore reads caller-supplied token identifiers from the shared Core Token Store (CTS) without an OAuth-only namespace, and the OAuthAdapter accepts a row whose BLOB claims to contain an OAuth token without binding the trusted CTS type or verifying integrity. When an attacker can place controlled JSON in the CTS under a known token identifier – for example, via Push Registration followed by an anonymous SNS callback in an enabled realm – they can mint OAuth bearer tokens and OpenID Connect ID tokens with chosen subject, client, realm, and scope. The flaw does not create an OpenAM single sign‑on session or grant console access by itself, but it allows the creation of valid tokens that may be used for unauthorized access to protected resources.

Affected Systems

OpenIdentityPlatform's OpenAM, versions earlier than 16.1.1, can be affected if the Push Registration and anonymous SNS callback features are enabled.

Risk and Exploitability

The CVSS score of 7.6 indicates a medium to high severity vulnerability. With an EPSS score of less than 1 %, the likelihood of exploitation is low at present, and it is not listed in CISA's KEV catalog. The attack would require successful manipulation of the Core Token Store through Push Registration, implying a network-facing vector that could be mitigated by disabling or restricting these functions. If exploited, the attacker can obtain valid access tokens for arbitrary subjects and scopes, potentially accessing protected APIs and resources.

Generated by OpenCVE AI on September 17, 2026 at 17:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenAM to version 16.1.1 or later.
  • If an update is not possible, disable Push Registration and anonymous SNS callbacks in all enabled realms to prevent the injection of malicious token data.
  • Restrict write access to the Core Token Store and enforce OAuth-only namespaces to ensure token identifiers and credential blobs are only accepted from trusted sources.

Generated by OpenCVE AI on September 17, 2026 at 17:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-cj8f-2fhf-826r OpenAM Arbitrary OAuth Token Minting via Push Registration
History

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Openidentityplatform
Openidentityplatform openam
Vendors & Products Openidentityplatform
Openidentityplatform openam

Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied token identifiers from the shared Core Token Store (CTS) without an OAuth-only namespace, and OAuthAdapter accepts a row whose BLOB claims to contain an OAuth token without binding the trusted CTS type or verifying integrity. An attacker who can place controlled JSON in CTS under a known token identifier, such as through Push Registration followed by an anonymous SNS callback in an enabled realm, can mint OAuth bearer tokens and OpenID Connect ID tokens with chosen subject, client, realm, and scope. The flaw does not by itself create an OpenAM SSO session or grant console access. This issue is fixed in version 16.1.1.
Title OpenAM Arbitrary OAuth Token Minting via Push Registration
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T12:57:29.745Z

Reserved: 2026-05-14T18:06:06.812Z

Link: CVE-2026-46498

cve-icon Vulnrichment

Updated: 2026-09-15T12:57:24.503Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T10:17:04.623

Modified: 2026-09-23T18:21:42.327

Link: CVE-2026-46498

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key