2026-10-03 12:14CVE-2026-105121VulnCheck
PUBLISHED5.2CWE-285

OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping

OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.

Problem type

Affected products

OpenIdentityPlatform

OpenAM

< 16.1.3 - AFFECTED

16.1.3 - UNAFFECTED

References

GitHub Security Advisories

GHSA-86x4-hjp8-8h99

OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated...

https://github.com/advisories/GHSA-86x4-hjp8-8h99

OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-105121
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-105121",
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "dateUpdated": "2026-10-03T12:14:44.905Z",
    "dateReserved": "2026-10-03T12:04:36.964Z",
    "datePublished": "2026-10-03T12:14:44.905Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck",
        "dateUpdated": "2026-10-03T12:14:44.905Z"
      },
      "datePublic": "2026-09-18T00:00:00.000Z",
      "title": "OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping",
      "descriptions": [
        {
          "lang": "en",
          "value": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm."
        }
      ],
      "affected": [
        {
          "vendor": "OpenIdentityPlatform",
          "product": "OpenAM",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "semver",
              "lessThan": "16.1.3"
            },
            {
              "version": "16.1.3",
              "status": "unaffected",
              "versionType": "semver"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Improper Authorization",
              "cweId": "CWE-285",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-hmwh-9r8r-44gw",
          "name": "GitHub Security Advisory (GHSA-hmwh-9r8r-44gw)",
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-improper-authorization-in-delegated-session-destroy-realm-scoping",
          "name": "VulnCheck Advisory: OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping",
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS"
        },
        {
          "format": "CVSS",
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "availabilityImpact": "HIGH",
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM"
          }
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "arpitjain099",
          "type": "reporter"
        },
        {
          "lang": "en",
          "value": "maximthomas",
          "type": "finder"
        },
        {
          "lang": "en",
          "value": "tsujiguchitky",
          "type": "finder"
        }
      ]
    }
  }
}