Junglewise Threat Intelligence

CVE-2026-45052: Open Identity Platform OpenAM improper authorization in Liberty Discovery Endpoints

CVE-2026-45052 · Severity: critical · CVSS 9.3 · Published 2026-06-24

Executive brief

OpenAM is an open-source access management platform used to secure web applications and manage user identities. A security flaw in its legacy Liberty Web Services component allows unauthorized individuals to modify user profile data and system discovery records without a password. This could allow an attacker to redirect service traffic or manipulate security settings, potentially leading to unauthorized access or service disruption.

Technical details

An Improper Authorization (CWE-285) vulnerability exists in the Liberty Web Services SOAP receiver of OpenAM Community Edition. The Liberty Discovery handlers accept anonymous SOAP writes that are executed server-side using elevated internal privileges (including the internal admin token for global paths), effectively bypassing LDAP and identity-layer ACLs. An unauthenticated remote attacker can exploit this to inject persistent records into the Liberty Discovery store on any user's LDAP entry or the root-realm branch. While the Liberty ID-WSF protocol is legacy, it is enabled by default; successful exploitation can influence service routing or security mechanism selection. The issue is patched in version 16.1.1.

Affected products

  • Open Identity Platform OpenAM Community Edition <= 16.0.6

Timeline

  • 2026-06-24: advisory: GitHub Advisory GHSA-p462-xxwx-pqf4 published
  • 2026-06-24: patched: Vulnerability fixed in version 16.1.1

References

Related threats