๐Ÿ” CVE Alert

CVE-2026-44202

UNKNOWN 0.0

OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice`

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbitrary notification URL without requiring an administrative or application client token. SessionRequestHandler passes the attacker-controlled destination to the session listener service, causing the OpenAM server to make outbound requests and potentially disclose session-related notification data to an attacker-controlled destination. This issue is fixed in version 16.1.1.

CWE CWE-918
Vendor openidentityplatform
Product openam
Published Sep 15, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for openidentityplatform openam

Be the first to know when new unknown vulnerabilities affecting openidentityplatform openam are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OpenIdentityPlatform / OpenAM
< 16.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-c556-q2mh-477v github.com: https://github.com/OpenIdentityPlatform/OpenAM/commit/a13a4b63ae0e0670c63cbcfa79586407408b3920 github.com: https://github.com/OpenIdentityPlatform/OpenAM/releases/tag/16.1.1