Description
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler requires a code_verifier only when the realm-wide codeVerifierEnforced setting is enabled, even when an authorization code stores a code_challenge. Because that setting is disabled by default, an attacker who intercepts a PKCE-protected authorization code can omit code_verifier and redeem the code, while an explicitly incorrect verifier is rejected. Public clients are directly affected, and confidential-client exploitation additionally requires client authentication material or another redemption context. This issue is fixed in version 16.1.1.
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: OAuth Authorization Bypass
Action: Patch Immediately
AI Analysis

Impact

OpenAM’s AuthorizationCodeGrantTypeHandler incorrectly allows a PKCE protection code to be redeemed without a code_verifier when the realm-wide codeVerifierEnforced setting is disabled. An attacker who has intercepted a PKCE‑protected authorization code can omit the required code_verifier and redeem it, receiving access tokens that grant the attacker the authorization level of the original client. Public clients are directly affected; confidential clients can also be exploited if an attacker supplies valid client authentication material or additional redemption context. This bypass of the PKCE protocol provides untrusted access to protected resources and is a classic improper authorization flaw (CWE‑285). The issue is fixed in OpenAM version 16.1.1.

Affected Systems

The vulnerability affects OpenIdentityPlatform’s OpenAM up to version 16.1.0 inclusive. Public clients using OAuth 2.0 with PKCE are directly impacted; confidential clients can also be exploited if an attacker supplies valid client authentication or additional redemption context. The issue is mitigated in OpenAM 16.1.1 and later.

Risk and Exploitability

The CVSS score of 9.1 signals a high severity flaw. EPSS indicates a very low probability of exploitation, and the flaw is not listed in CISA’s KEV catalog. The likely attack path involves an adversary intercepting the authorization code over an insecure channel or through network compromise and then redeeming it without a verifier. However, without interception the flaw remains ineffective, so the risk is contingent on the ability to capture the code.

Generated by OpenCVE AI on September 17, 2026 at 18:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenAM to version 16.1.1 or later, which restores proper PKCE verification behavior.
  • Enable the realm‑wide setting `codeVerifierEnforced` to true for any realms that use PKCE so that a code_verifier is always required during token redemption.
  • Ensure that OAuth interactions are conducted over TLS so that authorization codes cannot be intercepted in transit.

Generated by OpenCVE AI on September 17, 2026 at 18:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4v2w-2wqp-mc85 OpenAM OAuth Authorization Bypass via PKCE Challenge
History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Openidentityplatform
Openidentityplatform openam
Vendors & Products Openidentityplatform
Openidentityplatform openam

Tue, 15 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Description Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler requires a code_verifier only when the realm-wide codeVerifierEnforced setting is enabled, even when an authorization code stores a code_challenge. Because that setting is disabled by default, an attacker who intercepts a PKCE-protected authorization code can omit code_verifier and redeem the code, while an explicitly incorrect verifier is rejected. Public clients are directly affected, and confidential-client exploitation additionally requires client authentication material or another redemption context. This issue is fixed in version 16.1.1.
Title OpenAM OAuth Authorization Bypass via PKCE Challenge
Weaknesses CWE-285
References
Metrics cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T13:52:56.107Z

Reserved: 2026-05-22T18:47:27.755Z

Link: CVE-2026-48717

cve-icon Vulnrichment

Updated: 2026-09-15T13:25:13.371Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T10:17:05.377

Modified: 2026-09-23T18:21:42.327

Link: CVE-2026-48717

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses