Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.openidentityplatform.openam/openam-oauth2
  4. ›
  5. CVE-2026-46498

CVE-2026-46498: OpenAM Arbitrary OAuth Token Minting via Push Registration

June 25, 2026

Description

An Authorization Bypass Through User-Controlled Key (CWE-639) exists in OpenAM’s stateful OAuth2 token-read path. Under certain conditions, this may allow an attacker to forge OAuth2 bearer tokens and OIDC ID tokens with arbitrary subject, client, realm, and scope. This affects OpenAM Community Edition through version 16.0.6.

The OAuth2 token-read path reads caller-supplied token identifiers from the shared Core Token Store (CTS) without placing them in an OAuth-only namespace and without binding the row’s trusted CTS type to the expected OAuth token family, so any CTS row whose BLOB claims to be an OAuth token is accepted on the read path with no integrity check.

References

  • github.com/OpenIdentityPlatform/OpenAM/releases/tag/16.1.1
  • github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-cj8f-2fhf-826r
  • github.com/advisories/GHSA-cj8f-2fhf-826r
  • nvd.nist.gov/vuln/detail/CVE-2026-46498

Code Behaviors & Features

Detect and mitigate CVE-2026-46498 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 16.1.1

Fixed versions

  • 16.1.1

Solution

Upgrade to version 16.1.1 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-639: Authorization Bypass Through User-Controlled Key

Source file

maven/org.openidentityplatform.openam/openam-oauth2/CVE-2026-46498.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Fri, 26 Jun 2026 12:17:29 +0000.