Description
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the request-supplied MSISDN value into an LDAP search filter without escaping, while the default empty trusted-gateway list allows all traffic. In a realm where an MSISDN module is enabled in a reachable authentication chain, an unauthenticated remote attacker can inject LDAP filter metacharacters, select an arbitrary matching user, and obtain a normal authenticated OpenAM session without a password. This issue is fixed in version 16.1.1.
Published: 2026-09-15
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Apply Patch
AI Analysis

Impact

OpenAM’s MSISDN authentication module does not escape the request‑supplied MSISDN value before inserting it into an LDAP search filter, and by default the trusted‑gateway list is empty allowing traffic from any host. Consequently an unauthenticated remote attacker can inject LDAP filter metacharacters into the MSISDN and manipulate the resulting query to match any user. By doing so, the attacker can create a valid OpenAM session without providing a password, thereby bypassing normal authentication controls. The bug is fixed in version 16.1.1.

Affected Systems

OpenIdentityPlatform’s OpenAM product, versions prior to 16.1.1, is affected. The vulnerability exists for any realm that has the MSISDN module enabled within an authentication chain that is reachable from the network. Users of older builds of OpenAM that have not applied the 16.1.1 update are at risk.

Risk and Exploitability

The CVSS score of 9.3 indicates a high severity impact, while the EPSS score of less than 1% suggests a very low current exploitation probability. Because the default trusted‑gateway list is empty, the vulnerability can be triggered by any externally reachable client, so the attack vector is likely remote. The issue is not listed in CISA’s KEV catalogue, meaning there are no confirmed active exploits known to date. Nonetheless, once exploited, the attacker gains the privileges of the matched user, leading to full access to the OpenAM session.

Generated by OpenCVE AI on September 17, 2026 at 17:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenAM to version 16.1.1 or later as released by OpenIdentityPlatform.
  • If an upgrade cannot be performed immediately, configure a trusted‑gateway list to allow only known, trusted hosts to access the authentication endpoint.
  • Implement input sanitization by escaping LDAP filter metacharacters in the MSISDN field before it is used in the search filter.

Generated by OpenCVE AI on September 17, 2026 at 17:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xq73-fvmr-jvmm OpenAM Authentication Bypass via MSISDN LDAP Injection
History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Openidentityplatform
Openidentityplatform openam
Vendors & Products Openidentityplatform
Openidentityplatform openam

Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the request-supplied MSISDN value into an LDAP search filter without escaping, while the default empty trusted-gateway list allows all traffic. In a realm where an MSISDN module is enabled in a reachable authentication chain, an unauthenticated remote attacker can inject LDAP filter metacharacters, select an arbitrary matching user, and obtain a normal authenticated OpenAM session without a password. This issue is fixed in version 16.1.1.
Title OpenAM Authentication Bypass via MSISDN LDAP Injection
Weaknesses CWE-90
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T14:23:05.955Z

Reserved: 2026-05-15T19:34:14.012Z

Link: CVE-2026-46619

cve-icon Vulnrichment

Updated: 2026-09-15T14:23:00.795Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T10:17:04.770

Modified: 2026-09-25T14:23:59.847

Link: CVE-2026-46619

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-90

    Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')