
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-46498 is an Authorization Bypass Through User-Controlled Key vulnerability (CWE-639) in OpenAM Community Edition's stateful OAuth2 token-read path, enabling an attacker to forge OAuth2 bearer tokens and OIDC ID tokens with arbitrary subject, client, realm, and scope. It affects OpenAM Community Edition through version 16.0.6 (Maven package org.openidentityplatform.openam:openam-oauth2). The vulnerability was published and patched on June 25, 2026, with the fix available in version 16.1.1. It carries a CVSS v4.0 base score of 7.1 (High) (Github Advisory, OpenAM Advisory).
The root cause (CWE-639) lies in OpenAM's stateful OAuth2 token-read path, which reads caller-supplied token identifiers from the shared Core Token Store (CTS) without placing them in an OAuth-only namespace and without binding the row's trusted CTS type to the expected OAuth token family. As a result, any CTS row whose BLOB claims to be an OAuth token is accepted on the read path with no integrity check. Exploitation requires a low-privileged attacker to first place attacker-controlled JSON into the shared CTS under a known identifier — a primitive achievable via the anonymous Push Notification SNS callback handler in Push Notification-enabled realms after a single legitimate Push registration. The attack is network-based, requires low privileges, and no user interaction (Github Advisory, OpenAM Advisory).
Successful exploitation allows an attacker to forge OAuth2 bearer tokens and OIDC ID tokens with attacker-chosen userName, clientID, realm, and scope, effectively impersonating any user or client within the affected realm. This can lead to unauthorized access to OAuth2-protected resources and APIs, privilege escalation within connected applications, and potential lateral movement across services that trust the forged tokens. Notably, the compromise does not by itself create an OpenAM SSO session or grant admin-console access, but the integrity of the OAuth2 authorization framework is fully undermined (Github Advisory).
userName, clientID, realm, and scope fields.The vulnerability has been patched in OpenAM Community Edition version 16.1.1, released June 17, 2026. All users running version 16.0.6 or earlier with the OAuth2 Provider service enabled should upgrade to 16.1.1 immediately. As a temporary workaround where upgrading is not immediately possible, consider disabling the Push Notification service in affected realms to remove the CTS write primitive required for exploitation. Restricting network access to the Push Notification SNS callback handler endpoint can also reduce exposure (OpenAM Release, Github Advisory).
The vulnerability was reported by researcher wodzen, who also discovered several other significant vulnerabilities in OpenAM patched in the same 16.1.1 release (including session hijacking, RCE via deserialization, and authentication bypass issues). The OpenAM maintainers (vharseko) published the advisory and patch promptly on the same day. No broader media coverage or notable community commentary beyond the GitHub advisory has been identified at this time (OpenAM Release, OpenAM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."