OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.

cve CVE-2026-105121 2 sources, 2 claims · Watch

NVD writes:
OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm. the claim

What it is to other things

In words only, so not counted until a person confirms one:

affectsopenidentityplatform/openam
NVD says “OpenIdentityPlatform · OpenAM”
made_byopenidentityplatform
NVD says “OpenIdentityPlatform”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
GitHub advisories4.9
receipt
Source
GitHub advisories
Its words
4.9
Read by
field:cvss.score
Said since
2026-10-03 18:07 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-105121",
  "cvss": {
    "score": 4.9,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 4.9,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
    },
    "cvss_v4": {
      "score": 6.9,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-285",
      "name": "Improper Authorization"
    }
  ],
  "description": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.",
  "ghsa_id": "GHSA-86x4-hjp8-8h99",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-86x4-hjp8-8h99",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-86x4-hjp8-8h99"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-105121"
    }
  ],
  "nvd_published_at": "2026-10-03T14:16:38Z",
  "published_at": "2026-10-03T15:30:26Z",
  "references": [
    "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-hmwh-9r8r-44gw",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-105121",
    "https://www.vulncheck.com/advisories/openam-before-16.1.3-improper-authorization-in-delegated-session-destroy-realm-scoping",
    "https://github.com/advisories/GHSA-86x4-hjp8-8h99"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated...",
  "type": "unreviewed",
  "updated_at": "2026-10-03T15:30:26Z",
  "url": "https://api.github.com/advisories/GHSA-86x4-hjp8-8h99",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Cvss
cvss
NVD4.9
receipt
Source
NVD
Its words
4.9
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-03 18:10 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "packageURL": "pkg:maven/org.openidentityplatform.openam/openam-core",
            "product": "OpenAM",
            "vendor": "OpenIdentityPlatform",
            "versions": [
              {
                "lessThan": "16.1.3",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "16.1.3",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm."
      }
    ],
    "id": "CVE-2026-105121",
    "lastModified": "2026-10-03T14:16:38.997",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 3.6,
          "source": "disclosure@vulncheck.com",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-03T14:16:38.997",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-hmwh-9r8r-44gw"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-improper-authorization-in-delegated-session-destroy-realm-scoping"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-285"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Primary"
      }
    ]
  }
}
—
Cwe
cwe
GitHub advisoriesCWE-285
receipt
Source
GitHub advisories
Its words
CWE-285
Read by
field:cwes[].cwe_id
Said since
2026-10-03 18:07 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-105121",
  "cvss": {
    "score": 4.9,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 4.9,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
    },
    "cvss_v4": {
      "score": 6.9,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-285",
      "name": "Improper Authorization"
    }
  ],
  "description": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.",
  "ghsa_id": "GHSA-86x4-hjp8-8h99",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-86x4-hjp8-8h99",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-86x4-hjp8-8h99"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-105121"
    }
  ],
  "nvd_published_at": "2026-10-03T14:16:38Z",
  "published_at": "2026-10-03T15:30:26Z",
  "references": [
    "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-hmwh-9r8r-44gw",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-105121",
    "https://www.vulncheck.com/advisories/openam-before-16.1.3-improper-authorization-in-delegated-session-destroy-realm-scoping",
    "https://github.com/advisories/GHSA-86x4-hjp8-8h99"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated...",
  "type": "unreviewed",
  "updated_at": "2026-10-03T15:30:26Z",
  "url": "https://api.github.com/advisories/GHSA-86x4-hjp8-8h99",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Product
product
NVDOpenAM
receipt
Source
NVD
Its words
OpenAM
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-03 18:10 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "packageURL": "pkg:maven/org.openidentityplatform.openam/openam-core",
            "product": "OpenAM",
            "vendor": "OpenIdentityPlatform",
            "versions": [
              {
                "lessThan": "16.1.3",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "16.1.3",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm."
      }
    ],
    "id": "CVE-2026-105121",
    "lastModified": "2026-10-03T14:16:38.997",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 3.6,
          "source": "disclosure@vulncheck.com",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-03T14:16:38.997",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-hmwh-9r8r-44gw"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-improper-authorization-in-delegated-session-destroy-realm-scoping"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-285"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Primary"
      }
    ]
  }
}
—
Severity
severity
GitHub advisoriesmedium
receipt
Source
GitHub advisories
Its words
medium
Read by
field:severity
Said since
2026-10-03 18:07 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-105121",
  "cvss": {
    "score": 4.9,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 4.9,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
    },
    "cvss_v4": {
      "score": 6.9,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-285",
      "name": "Improper Authorization"
    }
  ],
  "description": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.",
  "ghsa_id": "GHSA-86x4-hjp8-8h99",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-86x4-hjp8-8h99",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-86x4-hjp8-8h99"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-105121"
    }
  ],
  "nvd_published_at": "2026-10-03T14:16:38Z",
  "published_at": "2026-10-03T15:30:26Z",
  "references": [
    "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-hmwh-9r8r-44gw",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-105121",
    "https://www.vulncheck.com/advisories/openam-before-16.1.3-improper-authorization-in-delegated-session-destroy-realm-scoping",
    "https://github.com/advisories/GHSA-86x4-hjp8-8h99"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated...",
  "type": "unreviewed",
  "updated_at": "2026-10-03T15:30:26Z",
  "url": "https://api.github.com/advisories/GHSA-86x4-hjp8-8h99",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Status
status
NVDReceived
receipt
Source
NVD
Its words
Received
Read by
field:cve.vulnStatus
Said since
2026-10-03 18:10 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "packageURL": "pkg:maven/org.openidentityplatform.openam/openam-core",
            "product": "OpenAM",
            "vendor": "OpenIdentityPlatform",
            "versions": [
              {
                "lessThan": "16.1.3",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "16.1.3",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm."
      }
    ],
    "id": "CVE-2026-105121",
    "lastModified": "2026-10-03T14:16:38.997",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 3.6,
          "source": "disclosure@vulncheck.com",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-03T14:16:38.997",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-hmwh-9r8r-44gw"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-improper-authorization-in-delegated-session-destroy-realm-scoping"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-285"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Primary"
      }
    ]
  }
}
—
Vendor
vendor
NVDOpenIdentityPlatform
receipt
Source
NVD
Its words
OpenIdentityPlatform
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-03 18:10 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "packageURL": "pkg:maven/org.openidentityplatform.openam/openam-core",
            "product": "OpenAM",
            "vendor": "OpenIdentityPlatform",
            "versions": [
              {
                "lessThan": "16.1.3",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "16.1.3",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm."
      }
    ],
    "id": "CVE-2026-105121",
    "lastModified": "2026-10-03T14:16:38.997",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 3.6,
          "source": "disclosure@vulncheck.com",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-03T14:16:38.997",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-hmwh-9r8r-44gw"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-improper-authorization-in-delegated-session-destroy-realm-scoping"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-285"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Primary"
      }
    ]
  }
}
—

vulnerability

OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.
zetlyn/cve-nvd · 2026-10-03
cvss 4.9 product OpenAM status Received vendor OpenIdentityPlatform source
OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated...
zetlyn/cve-ghsa · 2026-10-03
cvss 4.9 cwe CWE-285 severity medium source