Sceawere

Vulnerability Detail

CVE-2026-105120UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenAM Authorization Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.9
Creation Date
2h ago
Vendor
OpenIdentityPlatform
Product
OpenAM
Attack Type
Exposure of Sensitive Information to an Unauthorized Actor
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding delegated RealmAdmin privileges can supply a _queryFilter naming another realm to disclose usernames, universal IDs, and session handles across tenant boundaries.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.9",
  "pubDate": "2026-10-03T14:16:38.853Z",
  "pubdate": "2026-10-03T14:16:38.853Z",
  "executiveSummary": "OpenAM versions prior to 16.1.3 are susceptible to an authorization bypass vulnerability within the sessions REST endpoint query functionality. The flaw allows authenticated users with delegated RealmAdmin privileges to execute queries that traverse across administrative boundaries.\nBy manipulating the _queryFilter parameter, a malicious actor can bypass intended authorization constraints, facilitating the unauthorized retrieval of sensitive data from realms outside their delegated scope. This vulnerability effectively permits the cross-tenant disclosure of personally identifiable information and session metadata.\nImpacted information includes usernames, universal identifiers (UUIDs), and session handles. The exploitation of this vulnerability results in significant information leakage, undermining multi-tenancy isolation and tenant segregation security controls. The primary risk implication is the compromise of administrative compartmentalization, which could facilitate further reconnaissance or lateral movement within the identity management infrastructure.\nExploitation requires the attacker to possess valid RealmAdmin credentials for a subordinate or peer realm. No further interaction from high-privileged administrators is required once the malicious query is crafted and submitted to the target endpoint.",
  "technicalDetails": "The vulnerability resides in the sessions REST endpoint's processing logic, specifically in how the query operation interprets and applies the _queryFilter parameter. The root cause is a failure in the authorization layer to correctly validate or sanitize the target realm scope during the execution of query operations initiated by a delegated RealmAdmin.\nIn a secure implementation, a RealmAdmin's request to list or filter sessions should be strictly confined to the specific realm to which they are assigned administrative permissions. However, in vulnerable versions of OpenAM, the underlying query handler fails to verify that the target realm specified or implied by the _queryFilter aligns with the authenticated user's authorization context. This allows an attacker to inject filter logic that escapes the logical boundary of their assigned tenant.\nThe attack flow proceeds as follows: First, the attacker authenticates as a legitimate RealmAdmin. Second, the attacker crafts a malicious HTTP GET request targeting the sessions REST endpoint, embedding a crafted _queryFilter parameter designed to target a different realm than the one authorized for the attacker. Third, because the authorization bypass occurs during the query execution phase, the backend service fails to enforce the tenant isolation policy. Consequently, the application processes the query against the unauthorized scope and retrieves session objects belonging to other realms.\nThe payload specifically interacts with the query parsing engine, which does not adequately restrict the search space for session lookups. This behavior facilitates the unauthorized extraction of session handles, usernames, and universal IDs across tenant boundaries. The exposure of session handles is particularly critical, as these identifiers are primary tokens used for maintaining state; unauthorized disclosure could potentially lead to session hijacking or provide the data necessary to conduct identity spoofing attacks within the identity provider infrastructure.\nThe vulnerability is limited to authenticated environments where delegated administration is active; it does not represent an unauthenticated remote code execution vector. However, it represents a severe breakdown of the application's multi-tenancy model, turning a legitimate administrative function into a data exfiltration tool. The issue is persistent across all deployments utilizing OpenAM versions before 16.1.3 that rely on the affected REST session services."
}