Description
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated server-side script author to escape the scripting sandbox despite the default class allow and deny lists. A user such as a sub-realm RealmAdmin who can create or edit a script in an executed context can invoke operating-system commands as the OpenAM application server account, crossing the realm-scoped administration boundary and compromising the JVM and every realm it serves. This issue is fixed in version 16.1.1.
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

The vulnerability allows an authenticated server‑side script author to escape the Groovy sandbox in OpenAM. Prior to version 16.1.1, the GroovySandboxValueFilter permits script authors, such as RealmAdmins who can create or edit scripts, to bypass the default class allow and deny lists. By doing so, they can invoke arbitrary operating‑system commands under the OpenAM application server account, crossing the realm‑scoped administration boundary and compromising the JVM and every realm served by the instance. The weakness is a security misconfiguration (CWE‑693).

Affected Systems

Affected releases are any OpenAM versions earlier than 16.1.1. The issue is fixed in OpenAM 16.1.1, so systems running 16.0.x or earlier are vulnerable. The product is OpenIdentityPlatform’s OpenAM, an access‑management solution.

Risk and Exploitability

The CVSS score of 7.5 indicates a high risk, while the EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability requires an attacker to have authenticated access and the ability to create or edit scripts, usually through realm‑level administrative rights. Once exploited, the attacker can execute commands at the server level, potentially achieving full system compromise. It is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 17, 2026 at 17:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenAM to version 16.1.1 or later, which removes the Groovy sandbox escape flaw.
  • Limit script‑authoring permissions to only trusted users or disable script execution if not needed.
  • Audit existing scripts and remove any that rely on elevated privileges or that were created before the patch.

Generated by OpenCVE AI on September 17, 2026 at 17:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-69j4-qvqr-hpw3 OpenAM Authenticated RCE via Groovy Sandbox Escape
History

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Openidentityplatform
Openidentityplatform openam
Vendors & Products Openidentityplatform
Openidentityplatform openam

Tue, 15 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Description Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated server-side script author to escape the scripting sandbox despite the default class allow and deny lists. A user such as a sub-realm RealmAdmin who can create or edit a script in an executed context can invoke operating-system commands as the OpenAM application server account, crossing the realm-scoped administration boundary and compromising the JVM and every realm it serves. This issue is fixed in version 16.1.1.
Title OpenAM Authenticated RCE via Groovy Sandbox Escape
Weaknesses CWE-693
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T12:47:22.878Z

Reserved: 2026-05-19T19:37:43.526Z

Link: CVE-2026-47424

cve-icon Vulnrichment

Updated: 2026-09-15T12:46:59.977Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T10:17:05.077

Modified: 2026-09-23T18:21:42.327

Link: CVE-2026-47424

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure