OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated...

zetlyn/cve-ghsa vulnerability ghsa GHSA-86x4-hjp8-8h99 cve CVE-2026-105121 known 2026-10-03

https://github.com/advisories/GHSA-86x4-hjp8-8h99

Properties

cvss4.9
receipt
Source
GitHub advisories
Its words
4.9
Read by
field:cvss.score
Said since
2026-10-03 18:07 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-105121",
  "cvss": {
    "score": 4.9,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 4.9,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
    },
    "cvss_v4": {
      "score": 6.9,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-285",
      "name": "Improper Authorization"
    }
  ],
  "description": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.",
  "ghsa_id": "GHSA-86x4-hjp8-8h99",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-86x4-hjp8-8h99",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-86x4-hjp8-8h99"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-105121"
    }
  ],
  "nvd_published_at": "2026-10-03T14:16:38Z",
  "published_at": "2026-10-03T15:30:26Z",
  "references": [
    "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-hmwh-9r8r-44gw",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-105121",
    "https://www.vulncheck.com/advisories/openam-before-16.1.3-improper-authorization-in-delegated-session-destroy-realm-scoping",
    "https://github.com/advisories/GHSA-86x4-hjp8-8h99"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated...",
  "type": "unreviewed",
  "updated_at": "2026-10-03T15:30:26Z",
  "url": "https://api.github.com/advisories/GHSA-86x4-hjp8-8h99",
  "vulnerabilities": [],
  "withdrawn_at": null
}
cweCWE-285
receipt
Source
GitHub advisories
Its words
CWE-285
Read by
field:cwes[].cwe_id
Said since
2026-10-03 18:07 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-105121",
  "cvss": {
    "score": 4.9,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 4.9,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
    },
    "cvss_v4": {
      "score": 6.9,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-285",
      "name": "Improper Authorization"
    }
  ],
  "description": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.",
  "ghsa_id": "GHSA-86x4-hjp8-8h99",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-86x4-hjp8-8h99",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-86x4-hjp8-8h99"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-105121"
    }
  ],
  "nvd_published_at": "2026-10-03T14:16:38Z",
  "published_at": "2026-10-03T15:30:26Z",
  "references": [
    "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-hmwh-9r8r-44gw",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-105121",
    "https://www.vulncheck.com/advisories/openam-before-16.1.3-improper-authorization-in-delegated-session-destroy-realm-scoping",
    "https://github.com/advisories/GHSA-86x4-hjp8-8h99"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated...",
  "type": "unreviewed",
  "updated_at": "2026-10-03T15:30:26Z",
  "url": "https://api.github.com/advisories/GHSA-86x4-hjp8-8h99",
  "vulnerabilities": [],
  "withdrawn_at": null
}
severitymedium
receipt
Source
GitHub advisories
Its words
medium
Read by
field:severity
Said since
2026-10-03 18:07 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-105121",
  "cvss": {
    "score": 4.9,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 4.9,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
    },
    "cvss_v4": {
      "score": 6.9,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-285",
      "name": "Improper Authorization"
    }
  ],
  "description": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.",
  "ghsa_id": "GHSA-86x4-hjp8-8h99",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-86x4-hjp8-8h99",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-86x4-hjp8-8h99"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-105121"
    }
  ],
  "nvd_published_at": "2026-10-03T14:16:38Z",
  "published_at": "2026-10-03T15:30:26Z",
  "references": [
    "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-hmwh-9r8r-44gw",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-105121",
    "https://www.vulncheck.com/advisories/openam-before-16.1.3-improper-authorization-in-delegated-session-destroy-realm-scoping",
    "https://github.com/advisories/GHSA-86x4-hjp8-8h99"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated...",
  "type": "unreviewed",
  "updated_at": "2026-10-03T15:30:26Z",
  "url": "https://api.github.com/advisories/GHSA-86x4-hjp8-8h99",
  "vulnerabilities": [],
  "withdrawn_at": null
}

Text

OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated... OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.