Description
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and therefore constrains only an AuthenticatorImpl root object. A pre-authentication attacker can supply a userHandle whose serialized graph has a valid AuthenticatorImpl root and a nested gadget class, causing readObject or readResolve execution before the cast and assertion verification when a usable gadget is on the classpath. This bypasses the incomplete remediation for the earlier WebAuthn deserialization vulnerability. This issue is fixed in version 16.1.2.
Published: 2026-09-15
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The flaw resides in OpenAM’s WebAuthnAuthentication.deserialize method, which applies an ObjectInputFilter that allows every serialized object at depth greater than one, constraining only the root AuthenticatorImpl object. A pre‑authentication attacker can supply a userHandle whose serialized graph has a valid AuthenticatorImpl root and a nested gadget class, causing readObject or readResolve execution before cast and assertion verification when a usable gadget is present on the classpath. This bypasses the incomplete remediation for earlier WebAuthn deserialization vulnerabilities, and the vulnerability therefore permits remote code execution on affected servers. The issue is fixed in OpenAM 16.1.2.

Affected Systems

OpenIdentityPlatform OpenAM versions earlier than 16.1.2 are affected. The security fix is included in the 16.1.2 release.

Risk and Exploitability

The CVSS score of 9.2 indicates high severity, and the EPSS score of less than 1% suggests exploitation is currently rare, but the vulnerability was not listed in CISA KEV. The attack vector is a network‑based pre‑authentication request to OpenAM’s WebAuthn endpoint, requiring that a malicious gadget class be available on the Java classpath. Successful exploitation would grant an attacker unrestricted access to the application server and the ability to run arbitrary code.

Generated by OpenCVE AI on September 17, 2026 at 17:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenAM to version 16.1.2 or later, which implements proper ObjectInputFilter handling for WebAuthn deserialization
  • Disable or restrict the WebAuthn functionality on the server until the upgrade is complete, for example by removing the relevant module or blocking the WebAuthn endpoint with network controls
  • Remove any custom or third‑party gadget classes from the application’s classpath so that even if deserialization occurs no exploitable payload can execute

Generated by OpenCVE AI on September 17, 2026 at 17:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-gf8h-gq53-288j OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass
History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Openidentityplatform
Openidentityplatform openam
Vendors & Products Openidentityplatform
Openidentityplatform openam

Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and therefore constrains only an AuthenticatorImpl root object. A pre-authentication attacker can supply a userHandle whose serialized graph has a valid AuthenticatorImpl root and a nested gadget class, causing readObject or readResolve execution before the cast and assertion verification when a usable gadget is on the classpath. This bypasses the incomplete remediation for the earlier WebAuthn deserialization vulnerability. This issue is fixed in version 16.1.2.
Title OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass
Weaknesses CWE-502
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T13:53:17.927Z

Reserved: 2026-07-13T17:09:57.574Z

Link: CVE-2026-62263

cve-icon Vulnrichment

Updated: 2026-09-15T13:26:17.930Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T10:17:05.810

Modified: 2026-09-23T18:21:42.327

Link: CVE-2026-62263

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data