logo

Critical Pre-Auth RCE Found in OpenAM Identity Platform

ID: 4320d7ca-0f63-59ac-b25d-90ab600dedf4

STIX ID: report--4320d7ca-0f63-59ac-b25d-90ab600dedf4

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-04-17

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical pre-authentication RCE (CVE-2026-33439, CVSS 9.3) was found in OpenIdentityPlatform OpenAM (16.0.5 and possibly earlier) due to unsafe Java deserialization of the jato.clientSession parameter; an attacker can send a crafted serialized object to JATO ViewBean endpoints (e.g., password reset pages) to trigger a gadget chain that loads attacker bytecode and executes OS commands, enabling full server compromise. Administrators are urged to apply WhitelistObjectInputStream filtering to ClientSession.deserializeAttributes(), audit Encoder.deserialize() usage, and consider JVM-wide JEP 290 deserialization filters.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.