Critical Pre-Auth RCE Found in OpenAM Identity Platform
ID: 4320d7ca-0f63-59ac-b25d-90ab600dedf4
STIX ID: report--4320d7ca-0f63-59ac-b25d-90ab600dedf4
Feed Name: securityonline.info
A critical pre-authentication RCE (CVE-2026-33439, CVSS 9.3) was found in OpenIdentityPlatform OpenAM (16.0.5 and possibly earlier) due to unsafe Java deserialization of the jato.clientSession parameter; an attacker can send a crafted serialized object to JATO ViewBean endpoints (e.g., password reset pages) to trigger a gadget chain that loads attacker bytecode and executes OS commands, enabling full server compromise. Administrators are urged to apply WhitelistObjectInputStream filtering to ClientSession.deserializeAttributes(), audit Encoder.deserialize() usage, and consider JVM-wide JEP 290 deserialization filters.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
