CVE-2026-105120
published 2026-10-03CVE-2026-105120: OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list…
PriorityP430medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
0.26%
16.7th percentile
OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding delegated RealmAdmin privileges can supply a _queryFilter naming another realm to disclose usernames, universal IDs, and session handles across tenant boundaries.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openidentityplatform | openam | < 16.1.3 | 16.1.3 |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenIdentityPlatform OpenAM up to 16.1.2 Sessions REST Endpoint _queryFilter authorization
vuldb·2026-10-03·CVSS 4.9
CVE-2026-105120 [MEDIUM] OpenIdentityPlatform OpenAM up to 16.1.2 Sessions REST Endpoint _queryFilter authorization
A vulnerability was found in OpenIdentityPlatform OpenAM up to 16.1.2. It has been classified as problematic. This affects an unknown function of the component Sessions REST Endpoint. Performing a manipulation of the argument _queryFilter results in authorization bypass.
This vulnerability is known as CVE-2026-105120. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
GHSA
OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm.
ghsa_unreviewed·2026-10-03
CVE-2026-105120 [MEDIUM] CWE-200 OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm.
OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding delegated RealmAdmin privileges can supply a _queryFilter naming another realm to disclose usernames, universal IDs, and session handles across tenant boundaries.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-10-03
Published