Description
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and inetUserStatus, rewriting the password to the username and reactivating disabled accounts. The missing OAuth.removeRestrictedAccountUpdateAttributes filtering permits these credential and status fields to reach the account update. With account creation enabled, repeated OAuth login causes the default ldapService chain to accept the username as both identifier and password, allowing an unauthenticated attacker to take over the local account without interacting with the identity provider. The rewrite can be denied for usernames shorter than the configured minimum password length. This issue is fixed in version 16.1.1.
Published: 2026-09-15
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Account takeover via unauthenticated OAuth login
Action: Immediate Patch
AI Analysis

Impact

OpenAM's OAuth2 authentication module updates local accounts using profile attributes that include userPassword and inetUserStatus without applying the OAuth.removeRestrictedAccountUpdateAttributes filter. The result is that an attacker can rewrite a user’s password to match the username and reactivate disabled accounts. When account creation is enabled, repeated OAuth logins cause the default LDAP service chain to accept the username as both identifier and password, permitting an unauthenticated attacker to take over the local account without interacting with the identity provider. The vulnerability is mitigated for usernames shorter than the configured minimum password length, and version 16.1.1 contains a fix that restores the proper filtering and password‑rewrite logic.

Affected Systems

OpenIdentityPlatform OpenAM releases prior to version 16.1.1 are affected. Any installation using the OAuth2 authentication module in these earlier releases, such as OpenAM 16.0.x and earlier, may be vulnerable unless the account update filter has been customized.

Risk and Exploitability

The CVSS score of 7.4 indicates high severity, and the EPSS score below 1% suggests low observed exploitation risk at present. The vulnerability is not listed in the CISA KEV catalog. Nonetheless, the attack path does not require any authentication and can be triggered with simple OAuth logins, so an unauthenticated attacker can potentially take over a local account by exploiting the missing attribute filter and default LDAP authentication flow.

Generated by OpenCVE AI on September 17, 2026 at 17:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to OpenAM 16.1.1 or later, which restores the removeRestrictedAccountUpdateAttributes filter and corrects the password rewrite logic.
  • Disable automatic account creation or enforce stricter minimum password lengths until the update is applied, preventing the LDAP service from accepting weak credentials.
  • Verify that the OAuth.removeRestrictedAccountUpdateAttributes filter is active and excludes userPassword and inetUserStatus from account updates; if the filter is missing, manually configure it or block OAuth password changes until the patch is deployed.

Generated by OpenCVE AI on September 17, 2026 at 17:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-gf57-4mp6-m85x OpenAM Account Takeover via Unverified Password Change in OAuth2 Module
History

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Openidentityplatform
Openidentityplatform openam
Vendors & Products Openidentityplatform
Openidentityplatform openam

Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and inetUserStatus, rewriting the password to the username and reactivating disabled accounts. The missing OAuth.removeRestrictedAccountUpdateAttributes filtering permits these credential and status fields to reach the account update. With account creation enabled, repeated OAuth login causes the default ldapService chain to accept the username as both identifier and password, allowing an unauthenticated attacker to take over the local account without interacting with the identity provider. The rewrite can be denied for usernames shorter than the configured minimum password length. This issue is fixed in version 16.1.1.
Title OpenAM Account Takeover via Unverified Password Change in OAuth2 Module
Weaknesses CWE-1391
CWE-620
References
Metrics cvssV4_0

{'score': 7.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T14:08:44.260Z

Reserved: 2026-05-15T19:34:14.012Z

Link: CVE-2026-46623

cve-icon Vulnrichment

Updated: 2026-09-17T14:08:37.607Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T10:17:04.920

Modified: 2026-09-23T18:19:19.803

Link: CVE-2026-46623

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses