Org.openidentityplatform.openam:openam core: OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback (CVE-2026-62379)
A critical unauthenticated remote code execution vulnerability exists in OpenAM up to version 16.1.1. The vulnerability arises from the remote authentication endpoint (/authservice) accepting an XML element specifying an arbitrary Java class, which the server loads and instantiates without validation. This allows attackers to execute arbitrary code on the server without authentication. The issue is fixed in version 16.1.2. Interim mitigations include enabling the sunRemoteAuthSecurityEnabled setting to require a remote-auth security token and restricting external network access to /authservice until patched.
AI Analysis
Technical Summary
OpenAM versions prior to 16.1.2 contain a pre-authentication remote code execution vulnerability (CVE-2026-62379) in the AuthXMLUtils.createCustomCallback method. The /authservice endpoint accepts an XML element naming any Java class, which the server loads and instantiates without validation, allowing unauthenticated attackers to execute arbitrary code remotely. This vulnerability affects all releases up to and including 16.1.1 and predates the Open Identity Platform fork. The vulnerability is classified under CWE-470 (Use of Externally-Controlled Input to Select Classes or Code) and CWE-94 (Improper Control of Generation of Code).
Potential Impact
Successful exploitation allows unauthenticated remote code execution, resulting in full server compromise of any OpenAM instance running affected versions with default settings. This can lead to complete loss of confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
An official fix is available by upgrading to OpenAM version 16.1.2. Until the upgrade can be applied, enable the sunRemoteAuthSecurityEnabled setting to require the remote-auth security token, which blocks unauthenticated calls to /authservice. Additionally, restrict or block external network access to the /authservice endpoint to reduce exposure.
Org.openidentityplatform.openam:openam core: OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback (CVE-2026-62379)
Description
A critical unauthenticated remote code execution vulnerability exists in OpenAM up to version 16.1.1. The vulnerability arises from the remote authentication endpoint (/authservice) accepting an XML element specifying an arbitrary Java class, which the server loads and instantiates without validation. This allows attackers to execute arbitrary code on the server without authentication. The issue is fixed in version 16.1.2. Interim mitigations include enabling the sunRemoteAuthSecurityEnabled setting to require a remote-auth security token and restricting external network access to /authservice until patched.
CVSS v3.1
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OpenAM versions prior to 16.1.2 contain a pre-authentication remote code execution vulnerability (CVE-2026-62379) in the AuthXMLUtils.createCustomCallback method. The /authservice endpoint accepts an XML element naming any Java class, which the server loads and instantiates without validation, allowing unauthenticated attackers to execute arbitrary code remotely. This vulnerability affects all releases up to and including 16.1.1 and predates the Open Identity Platform fork. The vulnerability is classified under CWE-470 (Use of Externally-Controlled Input to Select Classes or Code) and CWE-94 (Improper Control of Generation of Code).
Potential Impact
Successful exploitation allows unauthenticated remote code execution, resulting in full server compromise of any OpenAM instance running affected versions with default settings. This can lead to complete loss of confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
An official fix is available by upgrading to OpenAM version 16.1.2. Until the upgrade can be applied, enable the sunRemoteAuthSecurityEnabled setting to require the remote-auth security token, which blocks unauthenticated calls to /authservice. Additionally, restrict or block external network access to the /authservice endpoint to reduce exposure.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-wg5r-wc3x-39vc
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-62379"]
- Ecosystems
- ["Maven"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6a6542309c2644c7f808a77c
Added to database: 07/25/2026, 23:09:36 UTC
Last enriched: 07/25/2026, 23:58:11 UTC
Last updated: 07/26/2026, 00:11:06 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.