Junglewise Threat Intelligence

CVE-2026-44202: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows a

CVE-2026-44202 · Severity: medium · CVSS 4 · Published 2026-09-15

Technologies: Open Identity Platform OpenAM, org.openidentityplatform.openam:openam-core (Maven). Vendors: Open Identity Platform, Maven.

Executive brief

OpenAM is an identity and access management platform used by organizations to manage user logins and single sign-on (SSO). A security flaw allows a logged-in user to trick the server into making unauthorized web requests to other internal or external systems. This could lead to the exposure of sensitive session data or allow an attacker to probe internal network resources that are normally hidden from the internet.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the OpenAM `/sessionservice` endpoint. The root cause is insufficient validation of URLs provided by authenticated users when registering for session event notifications. An attacker with valid credentials can register a malicious URL, causing the OpenAM server to initiate outbound requests to arbitrary destinations. This can be leveraged to perform internal port scanning, interact with internal services, or leak session-related data. The vulnerability is addressed in version 16.1.1.

Affected products

  • Open Identity Platform OpenAM (Open Identity Platform) <= 16.0.6

Timeline

  • 2026-06-17: patched: Version 16.1.1 released
  • 2026-06-20: disclosed
  • 2026-06-22: advisory

References

Related threats