Vendor
Open Identity Platform vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 22 vulnerabilities in Open Identity Platform: 0 in the last 7 days and 19 in the last 90 days, 7 of them critical and 0 exploited in the wild. The most recent, CVE-2026-46495, was published on 15 September 2026. 2 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 19
- Critical, all time
- 7
- Exploited in the wild
- 0
About Open Identity Platform
The Open Identity Platform community maintains open-source identity and access management solutions.
Open Identity Platform technologies
Latest Open Identity Platform vulnerabilities
- CVE-2026-46495: OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in…criticalCVSS 4EPSS 1.1%
- CVE-2026-62379: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL…criticalCVSS 9.8EPSS 1.1%
- CVE-2026-62280: Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize…mediumCVSS 6.1EPSS 0.3%
- CVE-2026-62263: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize…criticalCVSS 4EPSS 0.9%
- CVE-2026-53660: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes…highCVSS 4EPSS 0.4%
- CVE-2026-48717: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler…mediumCVSS 4EPSS 0.5%
- CVE-2026-47426: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client…highCVSS 4EPSS 0.5%
- CVE-2026-47424: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an…highCVSS 4EPSS 0.5%
- CVE-2026-46623: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module…highCVSS 4EPSS 0.7%
- CVE-2026-46619: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN…highCVSS 4EPSS 1.0%
- CVE-2026-46498: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied…highCVSS 4EPSS 0.4%
- CVE-2026-45794: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS…highCVSS 4EPSS 0.6%
- CVE-2026-45052: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver…criticalCVSS 4EPSS 0.8%
- CVE-2026-45051: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a…criticalCVSS 4EPSS 0.7%
- CVE-2026-45048: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session…highCVSS 8.5EPSS 0.4%
- CVE-2026-44793: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a…mediumCVSS 4EPSS 0.6%
- CVE-2026-44203: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect…criticalCVSS 9.3EPSS 0.6%
- CVE-2026-44202: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener…mediumCVSS 4EPSS 0.4%
- CVE-2026-41573: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection()…highCVSS 4EPSS 0.5%
- CVE-2026-46560: OpenIdentityPlatform OpenAM auth bypass in RADIUS modulehighCVSS 7.5
- CVE-2026-45049: Open Identity Platform OpenAM session hijacking in CDCServlethighCVSS 8.3
- CVE-2026-33439: OpenIdentityPlatform OpenAM Java deserialization RCE in jato.clientSessioncriticalCVSS 9.8EPSS 8.4%
Most severe Open Identity Platform vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-33439: OpenIdentityPlatform OpenAM Java deserialization RCE in jato.clientSessioncriticalCVSS 9.8EPSS 8.4%
- CVE-2026-62379: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL…criticalCVSS 9.8EPSS 1.1%
- CVE-2026-44203: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect…criticalCVSS 9.3EPSS 0.6%
- CVE-2026-46495: OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in…criticalCVSS 4EPSS 1.1%
- CVE-2026-62263: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize…criticalCVSS 4EPSS 0.9%
- CVE-2026-45052: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver…criticalCVSS 4EPSS 0.8%
- CVE-2026-45051: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a…criticalCVSS 4EPSS 0.7%
- CVE-2026-45048: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session…highCVSS 8.5EPSS 0.4%
- CVE-2026-45049: Open Identity Platform OpenAM session hijacking in CDCServlethighCVSS 8.3
- CVE-2026-46560: OpenIdentityPlatform OpenAM auth bypass in RADIUS modulehighCVSS 7.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 19 | 6 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/open-identity-platform.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Open Identity Platform vulnerabilities", https://junglewise.ai/threats/vendors/open-identity-platform, 26 September 2026.