๐Ÿ” CVE Alert

CVE-2026-45052

UNKNOWN 0.0

OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote requests to write persistent entries through SOAPReceiver and DiscoveryService into a user's Liberty Discovery store and the shared root-realm Discovery branch. The server-side handlers bypass requester LDAP and identity ACLs, and the global path uses an internal administrative token. Deployments that consume Liberty discovery data can subsequently use manipulated service-routing or security-mechanism records. This issue is fixed in version 16.1.1.

CWE CWE-285
Vendor openidentityplatform
Product openam
Published Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for openidentityplatform openam

Be the first to know when new unknown vulnerabilities affecting openidentityplatform openam are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OpenIdentityPlatform / OpenAM
< 16.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-p462-xxwx-pqf4 github.com: https://github.com/OpenIdentityPlatform/OpenAM/commit/07e402c3f6321fbe5ffdb213f3817f09a8fc81de github.com: https://github.com/OpenIdentityPlatform/OpenAM/releases/tag/16.1.1