ZeroHour

CVE-2026-45052

moderate

Unauthenticated Persistent Discovery-Store Injection in OpenAM Liberty SOAP Receiver

CVSS 4.0
9.3 critical
EPSS
Published
()
Modified
AI analysis

Open Access Management (OpenAM) versions prior to 16.1.1 contain an improper authorization flaw (CWE-285) in the Liberty Web Services (ID-WSF) SOAP receiver: the SOAPReceiver and DiscoveryService handlers accept unauthenticated remote requests and write persistent entries into a user's Liberty Discovery store and the shared root-realm Discovery branch. The server-side handlers bypass requester LDAP and identity ACLs, and the global path operates with an internal administrative token, so no credentials or user interaction are required (CVSS 4.0: 9.3, critical). An attacker gains the ability to plant or manipulate service-routing and security-mechanism records, and any deployment that consumes Liberty discovery data can subsequently act on attacker-controlled records, undermining downstream authentication and service-routing decisions. Organizations self-hosting OpenAM releases before 16.1.1 that have the Liberty web services endpoints reachable are affected; the issue is fixed in version 16.1.1. There is no known public proof of concept and no evidence of exploitation in the wild (not in CISA KEV).

What to do: Upgrade to OpenAM 16.1.1 or later, which fixes the flaw. Until patched, block or restrict external access to the Liberty Web Services SOAPReceiver and DiscoveryService endpoints at the reverse proxy or WAF, since they should never face untrusted networks. Audit the shared root-realm Discovery branch and user Liberty Discovery stores for unexpected service-routing or security-mechanism entries, and verify whether any downstream consumers rely on Liberty discovery data that may have been tampered with.

Affected
Open Identity Platform Open Access Management (OpenAM)prior to 16.1.1 (< 16.1.1)
Estimated exposure
moderatelow thousands of internet-reachable OpenAM servers (order of 1k-10k), with the actively vulnerable subset likely smaller since Liberty ID-WSF is a legacy… — OpenAM is a self-hosted, open-source enterprise identity product whose internet-exposed login/endpoint footprint in public scans (Shodan/Censys) is typically in the low thousands, and only deployments with the Liberty SOAP receiver…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote requests to write persistent entries through SOAPReceiver and DiscoveryService into a user's Liberty Discovery store and the shared root-realm Discovery branch. The server-side handlers bypass requester LDAP and identity ACLs, and the global path uses an internal administrative token. Deployments that consume Liberty discovery data can subsequently use manipulated service-routing or security-mechanism records. This issue is fixed in version 16.1.1.

Weakness
CWE-285
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.