CVE-2026-105121 MEDIUM

CVE-2026-105121: OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping

Vendor Openidentityplatform
Product OpenAM
Weakness CWE-285
Published October 3, 2026
Last update October 3, 2026

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.

Key dates

02Disclosure timeline

October 3, 2026 CVE published

Related vulnerabilities

04Related CVE