๐Ÿ” CVE Alert

CVE-2026-46623

UNKNOWN 0.0

OpenAM Account Takeover via Unverified Password Change in OAuth2 Module

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and inetUserStatus, rewriting the password to the username and reactivating disabled accounts. The missing OAuth.removeRestrictedAccountUpdateAttributes filtering permits these credential and status fields to reach the account update. With account creation enabled, repeated OAuth login causes the default ldapService chain to accept the username as both identifier and password, allowing an unauthenticated attacker to take over the local account without interacting with the identity provider. The rewrite can be denied for usernames shorter than the configured minimum password length. This issue is fixed in version 16.1.1.

CWE CWE-620 CWE-1391
Vendor openidentityplatform
Product openam
Published Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for openidentityplatform openam

Be the first to know when new unknown vulnerabilities affecting openidentityplatform openam are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OpenIdentityPlatform / OpenAM
< 16.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-gf57-4mp6-m85x github.com: https://github.com/OpenIdentityPlatform/OpenAM/commit/7993f6d2121c915a473415302b4c939e34b2842f github.com: https://github.com/OpenIdentityPlatform/OpenAM/releases/tag/16.1.1