CVE-2026-105121 PUBLISHED

OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping

Assigner: VulnCheck
Reserved: 03.10.2026 Published: 03.10.2026 Updated: 03.10.2026

OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor OpenIdentityPlatform
Product OpenAM
Versions Default: unaffected
  • affected from 0 to 16.1.3 (excl.)
  • Version 16.1.3 is unaffected

Credits

  • arpitjain099 reporter
  • maximthomas finder
  • tsujiguchitky finder

References

Problem Types

  • Improper Authorization CWE