Open Access Management (OpenAM) is an access management solution. (CVE-2026-45048)
Open Access Management (OpenAM) versions prior to 16.1.1 contain a vulnerability in the SessionRequestHandler component of the session management endpoint. This flaw allows a low-privileged authenticated user to bypass ownership and privilege checks when querying session information in deployments using stateful session storage. An attacker who knows a target identity identifier can retrieve active session credentials of another user, including those of more privileged accounts, enabling session hijacking. The issue is resolved in version 16.1.1.
AI Analysis
Technical Summary
CVE-2026-45048 affects OpenAM's SessionRequestHandler prior to version 16.1.1. The session management endpoint does not enforce proper ownership or privilege validation for session queries by low-privileged authenticated users in stateful session storage deployments. Consequently, an attacker with knowledge of a target identity identifier can access another user's active session credentials, including those of privileged accounts, and hijack their sessions. The issue is fixed in OpenAM version 16.1.1.
Potential Impact
An attacker with low privileges can retrieve active session credentials of other users, including privileged accounts, leading to session hijacking. This compromises confidentiality, integrity, and availability of affected sessions, potentially allowing unauthorized access and control over user accounts.
Mitigation Recommendations
Upgrade OpenAM to version 16.1.1 or later, where this vulnerability is fixed. No other mitigation is indicated by the vendor advisory.
Open Access Management (OpenAM) is an access management solution. (CVE-2026-45048)
Description
Open Access Management (OpenAM) versions prior to 16.1.1 contain a vulnerability in the SessionRequestHandler component of the session management endpoint. This flaw allows a low-privileged authenticated user to bypass ownership and privilege checks when querying session information in deployments using stateful session storage. An attacker who knows a target identity identifier can retrieve active session credentials of another user, including those of more privileged accounts, enabling session hijacking. The issue is resolved in version 16.1.1.
CVSS v3.1
Score 8.5high
Affected software
pkg:deb/ubuntu/openam?arch=source&distro=xenialRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-45048 affects OpenAM's SessionRequestHandler prior to version 16.1.1. The session management endpoint does not enforce proper ownership or privilege validation for session queries by low-privileged authenticated users in stateful session storage deployments. Consequently, an attacker with knowledge of a target identity identifier can access another user's active session credentials, including those of privileged accounts, and hijack their sessions. The issue is fixed in OpenAM version 16.1.1.
Potential Impact
An attacker with low privileges can retrieve active session credentials of other users, including privileged accounts, leading to session hijacking. This compromises confidentiality, integrity, and availability of affected sessions, potentially allowing unauthorized access and control over user accounts.
Mitigation Recommendations
Upgrade OpenAM to version 16.1.1 or later, where this vulnerability is fixed. No other mitigation is indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-45048
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:16.04:LTS"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab4be69f7a7c54106f0d423
Added to database: 09/24/2026, 06:08:41 UTC
Last enriched: 09/24/2026, 06:52:28 UTC
Last updated: 09/24/2026, 06:52:28 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.