Junglewise Threat Intelligence

CVE-2026-45051: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorIm

CVE-2026-45051 · Severity: critical · CVSS 9.2 · Published 2026-09-15

Executive brief

OpenAM is an open-source access management solution used to secure web applications and services. A security flaw in its WebAuthn module could allow an attacker to take complete control of the application server. This could lead to the theft of sensitive user data, service disruptions, or a total compromise of the corporate identity infrastructure.

Technical details

A Java deserialization vulnerability (CWE-502) exists in the OpenAM WebAuthn authentication module. The root cause is the unsafe deserialization of data retrieved from storage attributes (such as LDAP or directory records) during the WebAuthn authentication flow. While not the default configuration, the vulnerability is exploitable if an attacker can modify the storage attribute or if the 'userAttribute' is set to a user-writable field. An attacker can achieve arbitrary code execution in the context of the application server process. This issue is patched in OpenAM Community Edition version 16.1.1.

Affected products

  • OpenIdentityPlatform OpenAM Community Edition <= 16.0.6

Timeline

  • 2026-06-24: disclosed
  • 2026-06-24: advisory: GHSA-6c99-87fr-6q7r published

References

Related threats