PT-2026-104581 · Forgerock · Openam

·

CVE-2026-105120

·

Published

2026-10-03

·

Updated

2026-10-03

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenAM versions prior to 16.1.3
Description An authorization bypass exists in the sessions REST endpoint query operation. This issue allows users with delegated RealmAdmin privileges to list sessions across different realms by supplying a queryFilter that specifies another realm. This can lead to the disclosure of usernames, universal IDs, and session handles across tenant boundaries.
Recommendations Update to version 16.1.3 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105120

Affected Products

Openam