CVE-2026-47424
moderateGroovy Sandbox Escape in OpenAM Enables OS Command Execution by Realm Admins
Open Access Management (OpenAM) versions prior to 16.1.1 contain a flaw in GroovySandboxValueFilter that allows an authenticated server-side script author to escape the Groovy scripting sandbox even when the default class allow and deny lists are in place. The issue is triggered when a privileged user, such as a sub-realm RealmAdmin with permission to create or edit scripts in an executed context, submits a crafted script that bypasses the sandbox restrictions. Successful exploitation lets the attacker invoke operating-system commands as the OpenAM application server account, crossing the realm-scoped administration boundary and compromising the JVM and every realm it serves. Affected deployments are those running OpenAM before 16.1.1, particularly multi-tenant or multi-realm configurations where script-editing rights are delegated to realm-level administrators. There is no public proof of concept and the issue is not listed in CISA's KEV catalog, so exploitation status is currently unknown/none known.
What to do: Upgrade OpenAM to version 16.1.1 or later as soon as possible. In the interim, restrict who can create or edit scripts in executed contexts (remove script privileges from sub-realm RealmAdmin accounts where possible), and audit existing scripts for suspicious content such as OS command invocation or unexpected class usage. Review server logs and host telemetry for signs of command execution by the OpenAM application server account to rule out prior compromise.
| Open Identity Platform Community Open Access Management (OpenAM) | All versions prior to 16.1.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated server-side script author to escape the scripting sandbox despite the default class allow and deny lists. A user such as a sub-realm RealmAdmin who can create or edit a script in an executed context can invoke operating-system commands as the OpenAM application server account, crossing the realm-scoped administration boundary and compromising the JVM and every realm it serves. This issue is fixed in version 16.1.1.
- Weakness
- CWE-693
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.