Description
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentication path uses ClientJwksResolverCache without reliably binding a cached jwks_uri resolver and verified assertion to the expected clientID in ClientCredentialsReader. An attacker controlling any registered client with published keys, including one obtained through open dynamic registration when enabled, can authenticate as another client whose keys are exposed through jwks_uri and mint tokens in that client's name across realms in the same OpenAM process. This issue is fixed in version 16.1.1.
Published: 2026-09-15
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Client impersonation and token forgery
Action: Immediate Patch
AI Analysis

Impact

Prior to 16.1.1, the private_key_jwt client authentication path in OpenAM uses ClientJwksResolverCache without reliably binding a cached jwks_uri resolver and verified assertion to the expected clientID in ClientCredentialsReader. An attacker controlling any registered client with publicly exposed keys, including those obtained through open dynamic registration when enabled, can authenticate as another client whose keys are exposed via its jwks_uri and mint tokens in the target client’s name across realms within the same OpenAM process. The flaw allows the attacker to forge valid tokens on behalf of that client, enabling client impersonation and token forgery. The vulnerability is a weak authentication control identified as CWE‑287.

Affected Systems

The weakness affects the OpenIdentityPlatform OpenAM product. All OpenAM releases prior to version 16.1.1 are vulnerable, including OpenAM 16.0.x and earlier. Upgrading to 16.1.1 or a later release incorporates the fix.

Risk and Exploitability

The CVSS score of 7.6 indicates a high impact when the flaw is abused. The EPSS score of less than 1% reflects a low exploitation probability at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote and requires an adversary to control a legitimate client with exposed public keys, such as one obtained through dynamic client registration. Once that condition is met, the attacker can generate valid tokens in the victim client’s name, potentially accessing sensitive resources or abusing privilege escalation across realms. As the flaw enables unauthorized token issuances, the catastrophic consequences could be significant if the target client has elevated privileges.

Generated by OpenCVE AI on September 17, 2026 at 18:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenAM to version 16.1.1 or newer where the client authentication path correctly binds jwks_uri resolvers to the expected clientID.
  • If an upgrade cannot be performed immediately, restrict or disable dynamic client registration to prevent new clients with exposed keys from being registered.
  • Avoid publishing client JWKS URIs publicly; restrict access or enforce server‑side key validation to mitigate token forgery attempts.

Generated by OpenCVE AI on September 17, 2026 at 18:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-f2cx-463q-7m2c OpenAM OAuth Client Impersonation via JWKS Resolver Cache
History

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Openidentityplatform
Openidentityplatform openam
Vendors & Products Openidentityplatform
Openidentityplatform openam

Tue, 15 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Description Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentication path uses ClientJwksResolverCache without reliably binding a cached jwks_uri resolver and verified assertion to the expected clientID in ClientCredentialsReader. An attacker controlling any registered client with published keys, including one obtained through open dynamic registration when enabled, can authenticate as another client whose keys are exposed through jwks_uri and mint tokens in that client's name across realms in the same OpenAM process. This issue is fixed in version 16.1.1.
Title OpenAM OAuth Client Impersonation via JWKS Resolver Cache
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T14:11:08.346Z

Reserved: 2026-05-19T19:37:43.527Z

Link: CVE-2026-47426

cve-icon Vulnrichment

Updated: 2026-09-17T14:11:01.875Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T10:17:05.230

Modified: 2026-09-23T18:19:19.803

Link: CVE-2026-47426

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses