OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding delegated RealmAdmin privileges can supply a _queryFilter naming another realm to disclose usernames, universal IDs, and session handles across tenant boundaries.
OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpoint
Problem type
Affected products
OpenIdentityPlatform
< 16.1.3 - AFFECTED
16.1.3 - UNAFFECTED
< 16.1.3 - AFFECTED
16.1.3 - UNAFFECTED
References
https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-x8cj-3hqv-cgwh
https://www.vulncheck.com/advisories/openam-before-16.1.3-cross-realm-session-disclosure-via-sessions-rest-endpoint
GitHub Security Advisories
GHSA-55ch-4xvx-7w9q
OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint...
https://github.com/advisories/GHSA-55ch-4xvx-7w9qOpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding delegated RealmAdmin privileges can supply a _queryFilter naming another realm to disclose usernames, universal IDs, and session handles across tenant boundaries.
https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-x8cj-3hqv-cgwh
https://nvd.nist.gov/vuln/detail/CVE-2026-105120
https://www.vulncheck.com/advisories/openam-before-16.1.3-cross-realm-session-disclosure-via-sessions-rest-endpoint
https://github.com/advisories/GHSA-55ch-4xvx-7w9q
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-105120Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-105120",
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"dateUpdated": "2026-10-03T12:14:44.244Z",
"dateReserved": "2026-10-03T12:04:36.964Z",
"datePublished": "2026-10-03T12:14:44.244Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck",
"dateUpdated": "2026-10-03T12:14:44.244Z"
},
"datePublic": "2026-09-18T00:00:00.000Z",
"title": "OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpoint",
"descriptions": [
{
"lang": "en",
"value": "OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding delegated RealmAdmin privileges can supply a _queryFilter naming another realm to disclose usernames, universal IDs, and session handles across tenant boundaries."
}
],
"affected": [
{
"vendor": "OpenIdentityPlatform",
"product": "OpenAM",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "semver",
"lessThan": "16.1.3"
},
{
"version": "16.1.3",
"status": "unaffected",
"versionType": "semver"
}
]
},
{
"vendor": "OpenIdentityPlatform",
"product": "OpenAM",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "semver",
"lessThan": "16.1.3"
},
{
"version": "16.1.3",
"status": "unaffected",
"versionType": "semver"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "Exposure of Sensitive Information to an Unauthorized Actor",
"cweId": "CWE-200",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-x8cj-3hqv-cgwh",
"name": "GitHub Security Advisory (GHSA-x8cj-3hqv-cgwh)",
"tags": [
"vendor-advisory"
]
},
{
"url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-cross-realm-session-disclosure-via-sessions-rest-endpoint",
"name": "VulnCheck Advisory: OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpoint",
"tags": [
"third-party-advisory"
]
}
],
"metrics": [
{
"format": "CVSS"
},
{
"format": "CVSS",
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 4.9,
"baseSeverity": "MEDIUM"
}
}
],
"credits": [
{
"lang": "en",
"value": "vharseko",
"type": "finder"
},
{
"lang": "en",
"value": "maximthomas",
"type": "finder"
},
{
"lang": "en",
"value": "tsujiguchitky",
"type": "finder"
}
]
}
}
}