Description
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUtils to load and instantiate without verifying that it implements DSAMECallbackInterface. Default configurations expose the endpoint without authentication, allowing attacker-controlled class initialization and unsafe deserialization of a serialized Subject value to execute code in the server process. Enabling sunRemoteAuthSecurityEnabled does not prevent the vulnerable parsing and instantiation because its check occurs later. This issue is fixed in version 16.1.2.
Published: 2026-09-15
Score: 9.8 Critical
EPSS: 1.1% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A pre‑authentication endpoint in OpenAM accepts a CustomCallback XML element whose className field determines which Java class AuthXMLUtils will instantiate without performing any verification that the class implements the required interface. In default configurations the endpoint is exposed without authentication and the vulnerable code also deserializes a Subject value, allowing an attacker to load an arbitrary class, trigger unsafe deserialization, and execute code in the server process. The security setting sunRemoteAuthSecurityEnabled does not mitigate this behavior because its check occurs after the vulnerable parsing.

Affected Systems

OpenIdentityPlatform "OpenAM" versions prior to 16.1.2 are impacted. Any deployment that has not applied the 16.1.2 update or later exposes the /authservice PLL endpoint without authentication and remains vulnerable.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity. An EPSS score of roughly 1% suggests that while exploitation is possible, it is not widespread, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is unauthenticated network access to the vulnerable endpoint, making exploitation straightforward for an adversary who can send a crafted XML payload.

Generated by OpenCVE AI on September 17, 2026 at 17:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply2 patch or newer version to prevent arbitrary class loading and unsafe deserialization
  • Ensure the /authservice PLL endpoint is protected by authentication from the public interface
  • Verify that sunRemoteAuthSecurityEnabled is not being relied upon for this protection and re‑enable it only after the underlying issue is fixed

Generated by OpenCVE AI on September 17, 2026 at 17:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-wg5r-wc3x-39vc OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Openidentityplatform
Openidentityplatform openam
Vendors & Products Openidentityplatform
Openidentityplatform openam

Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUtils to load and instantiate without verifying that it implements DSAMECallbackInterface. Default configurations expose the endpoint without authentication, allowing attacker-controlled class initialization and unsafe deserialization of a serialized Subject value to execute code in the server process. Enabling sunRemoteAuthSecurityEnabled does not prevent the vulnerable parsing and instantiation because its check occurs later. This issue is fixed in version 16.1.2.
Title OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
Weaknesses CWE-470
CWE-94
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T14:21:34.543Z

Reserved: 2026-07-13T22:04:59.678Z

Link: CVE-2026-62379

cve-icon Vulnrichment

Updated: 2026-09-15T14:21:22.303Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T10:17:06.107

Modified: 2026-09-25T14:23:59.847

Link: CVE-2026-62379

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-470

    Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')