CVE-2026-45052
moderateUnauthenticated Persistent Discovery-Store Injection in OpenAM Liberty SOAP Receiver
Open Access Management (OpenAM) versions prior to 16.1.1 contain an improper authorization flaw (CWE-285) in the Liberty Web Services (ID-WSF) SOAP receiver: the SOAPReceiver and DiscoveryService handlers accept unauthenticated remote requests and write persistent entries into a user's Liberty Discovery store and the shared root-realm Discovery branch. The server-side handlers bypass requester LDAP and identity ACLs, and the global path operates with an internal administrative token, so no credentials or user interaction are required (CVSS 4.0: 9.3, critical). An attacker gains the ability to plant or manipulate service-routing and security-mechanism records, and any deployment that consumes Liberty discovery data can subsequently act on attacker-controlled records, undermining downstream authentication and service-routing decisions. Organizations self-hosting OpenAM releases before 16.1.1 that have the Liberty web services endpoints reachable are affected; the issue is fixed in version 16.1.1. There is no known public proof of concept and no evidence of exploitation in the wild (not in CISA KEV).
What to do: Upgrade to OpenAM 16.1.1 or later, which fixes the flaw. Until patched, block or restrict external access to the Liberty Web Services SOAPReceiver and DiscoveryService endpoints at the reverse proxy or WAF, since they should never face untrusted networks. Audit the shared root-realm Discovery branch and user Liberty Discovery stores for unexpected service-routing or security-mechanism entries, and verify whether any downstream consumers rely on Liberty discovery data that may have been tampered with.
| Open Identity Platform Open Access Management (OpenAM) | prior to 16.1.1 (< 16.1.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote requests to write persistent entries through SOAPReceiver and DiscoveryService into a user's Liberty Discovery store and the shared root-realm Discovery branch. The server-side handlers bypass requester LDAP and identity ACLs, and the global path uses an internal administrative token. Deployments that consume Liberty discovery data can subsequently use manipulated service-routing or security-mechanism records. This issue is fixed in version 16.1.1.
- Weakness
- CWE-285
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.