Impact
OpenAM's OAuth2 authentication module updates local accounts using profile attributes that include userPassword and inetUserStatus without applying the OAuth.removeRestrictedAccountUpdateAttributes filter. The result is that an attacker can rewrite a user’s password to match the username and reactivate disabled accounts. When account creation is enabled, repeated OAuth logins cause the default LDAP service chain to accept the username as both identifier and password, permitting an unauthenticated attacker to take over the local account without interacting with the identity provider. The vulnerability is mitigated for usernames shorter than the configured minimum password length, and version 16.1.1 contains a fix that restores the proper filtering and password‑rewrite logic.
Affected Systems
OpenIdentityPlatform OpenAM releases prior to version 16.1.1 are affected. Any installation using the OAuth2 authentication module in these earlier releases, such as OpenAM 16.0.x and earlier, may be vulnerable unless the account update filter has been customized.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity, and the EPSS score below 1% suggests low observed exploitation risk at present. The vulnerability is not listed in the CISA KEV catalog. Nonetheless, the attack path does not require any authentication and can be triggered with simple OAuth logins, so an unauthenticated attacker can potentially take over a local account by exploiting the missing attribute filter and default LDAP authentication flow.
OpenCVE Enrichment
Github GHSA