๐Ÿ” CVE Alert

CVE-2026-105121

MEDIUM 4.9

OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping

CVSS Score
4.9
EPSS Score
0.0%
EPSS Percentile
0th

OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.

CWE CWE-285
Vendor openidentityplatform
Product openam
Published Oct 3, 2026
Stay Ahead of the Next One

Get instant alerts for openidentityplatform openam

Be the first to know when new medium vulnerabilities affecting openidentityplatform openam are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

OpenIdentityPlatform / OpenAM
0 < 16.1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-hmwh-9r8r-44gw vulncheck.com: https://www.vulncheck.com/advisories/openam-before-16.1.3-improper-authorization-in-delegated-session-destroy-realm-scoping

Credits

๐Ÿ” arpitjain099 maximthomas tsujiguchitky