OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated...
zetlyn/cve-ghsa vulnerability ghsa GHSA-86x4-hjp8-8h99 cve CVE-2026-105121 known 2026-10-03
https://github.com/advisories/GHSA-86x4-hjp8-8h99
Properties
| cvss | 4.9receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-105121",
"cvss": {
"score": 4.9,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
},
"cvss_severities": {
"cvss_v3": {
"score": 4.9,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
},
"cvss_v4": {
"score": 6.9,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-285",
"name": "Improper Authorization"
}
],
"description": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.",
"ghsa_id": "GHSA-86x4-hjp8-8h99",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-86x4-hjp8-8h99",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-86x4-hjp8-8h99"
},
{
"type": "CVE",
"value": "CVE-2026-105121"
}
],
"nvd_published_at": "2026-10-03T14:16:38Z",
"published_at": "2026-10-03T15:30:26Z",
"references": [
"https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-hmwh-9r8r-44gw",
"https://nvd.nist.gov/vuln/detail/CVE-2026-105121",
"https://www.vulncheck.com/advisories/openam-before-16.1.3-improper-authorization-in-delegated-session-destroy-realm-scoping",
"https://github.com/advisories/GHSA-86x4-hjp8-8h99"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated...",
"type": "unreviewed",
"updated_at": "2026-10-03T15:30:26Z",
"url": "https://api.github.com/advisories/GHSA-86x4-hjp8-8h99",
"vulnerabilities": [],
"withdrawn_at": null
} |
|---|---|
| cwe | CWE-285receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-105121",
"cvss": {
"score": 4.9,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
},
"cvss_severities": {
"cvss_v3": {
"score": 4.9,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
},
"cvss_v4": {
"score": 6.9,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-285",
"name": "Improper Authorization"
}
],
"description": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.",
"ghsa_id": "GHSA-86x4-hjp8-8h99",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-86x4-hjp8-8h99",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-86x4-hjp8-8h99"
},
{
"type": "CVE",
"value": "CVE-2026-105121"
}
],
"nvd_published_at": "2026-10-03T14:16:38Z",
"published_at": "2026-10-03T15:30:26Z",
"references": [
"https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-hmwh-9r8r-44gw",
"https://nvd.nist.gov/vuln/detail/CVE-2026-105121",
"https://www.vulncheck.com/advisories/openam-before-16.1.3-improper-authorization-in-delegated-session-destroy-realm-scoping",
"https://github.com/advisories/GHSA-86x4-hjp8-8h99"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated...",
"type": "unreviewed",
"updated_at": "2026-10-03T15:30:26Z",
"url": "https://api.github.com/advisories/GHSA-86x4-hjp8-8h99",
"vulnerabilities": [],
"withdrawn_at": null
} |
| severity | mediumreceipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-105121",
"cvss": {
"score": 4.9,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
},
"cvss_severities": {
"cvss_v3": {
"score": 4.9,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
},
"cvss_v4": {
"score": 6.9,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-285",
"name": "Improper Authorization"
}
],
"description": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.",
"ghsa_id": "GHSA-86x4-hjp8-8h99",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-86x4-hjp8-8h99",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-86x4-hjp8-8h99"
},
{
"type": "CVE",
"value": "CVE-2026-105121"
}
],
"nvd_published_at": "2026-10-03T14:16:38Z",
"published_at": "2026-10-03T15:30:26Z",
"references": [
"https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-hmwh-9r8r-44gw",
"https://nvd.nist.gov/vuln/detail/CVE-2026-105121",
"https://www.vulncheck.com/advisories/openam-before-16.1.3-improper-authorization-in-delegated-session-destroy-realm-scoping",
"https://github.com/advisories/GHSA-86x4-hjp8-8h99"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated...",
"type": "unreviewed",
"updated_at": "2026-10-03T15:30:26Z",
"url": "https://api.github.com/advisories/GHSA-86x4-hjp8-8h99",
"vulnerabilities": [],
"withdrawn_at": null
} |
Text
OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated...
OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.