Executive brief
OpenText Access Manager, a solution used for managing user identities and secure access to applications, contains a vulnerability that allows unauthorized individuals to modify system configurations. By sending specific requests to the application's programming interface (API), an attacker could change settings without proper permission. This could potentially lead to unauthorized access or disruptions in how the organization manages user security.
Technical details
OpenText Access Manager is vulnerable to an incorrect use of privileged APIs (CWE-648). An unauthenticated remote attacker can leverage specific API calls to modify the application's configuration. The vulnerability exists in versions prior to 5.1.3. While the attack vector is network-based, the CVSS 4.0 score reflects a high attack complexity and specific technical preconditions. Successful exploitation allows for unauthorized integrity changes to the system configuration. Users are advised to upgrade to version 5.1.3 or later to remediate this issue.
Affected products
- OpenText Access Manager before 5.1.3
Timeline
- 2026-06-24: disclosed
- 2026-06-24: advisory