Junglewise Threat Intelligence

CVE-2026-45049: Open Identity Platform OpenAM session hijacking in CDCServlet

CVE-2026-45049 · Severity: high · CVSS 8.3 · Published 2026-06-23

Technologies: Open Identity Platform OpenAM Community Edition. Vendors: Maven, Open Identity Platform.

Executive brief

OpenAM is an identity and access management platform used to provide single sign-on (SSO) capabilities across different domains. A security flaw in its cross-domain component allows an attacker to steal a user's active login session if they can trick the user into clicking a malicious link. This could allow an attacker to impersonate the user and gain unauthorized access to corporate applications and sensitive data.

Technical details

An Information Exposure Through Sent Data (CWE-201) vulnerability exists in the OpenAM Cross-Domain Single Sign-On (CDSSO) servlet. The flaw allows a logged-in user's raw session token to be transmitted via a POST request to an attacker-controlled URL. Exploitation requires the CDSSO component to be enabled (common in multi-domain environments) and requires user interaction, where an authenticated victim is induced to visit a crafted URL. Successful exploitation results in session hijacking. The issue is present in OpenAM Community Edition through version 16.0.6 and was patched in version 16.1.1.

Affected products

  • Open Identity Platform OpenAM Community Edition <= 16.0.6

Timeline

  • 2026-06-23: disclosed
  • 2026-06-23: advisory
  • 16.1.1: patched: First patched version

References

Related threats