Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.openidentityplatform.openam/openam-auth-oauth2
  4. ›
  5. CVE-2026-46623

CVE-2026-46623: OpenAM Account Takeover via Unverified Password Change in OAuth2 Module

June 26, 2026

Description

An Unverified Password Change (CWE-620) and Use of Weak Credentials (CWE-1391) issue in OpenAM’s OAuth2 authentication module silently rewrites a local user’s password to the literal string of their username on OAuth2 re-login of an existing account. The default ldapService chain then accepts the username as the password for that user, allowing an unauthenticated attacker to obtain a session via the standard authenticate endpoint with both username and password set to the username, without any IdP interaction. This affects OpenAM Community Edition through version 16.0.6 and was patched in version 16.1.1.

References

  • github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-gf57-4mp6-m85x
  • github.com/advisories/GHSA-gf57-4mp6-m85x
  • nvd.nist.gov/vuln/detail/CVE-2026-46623

Code Behaviors & Features

Detect and mitigate CVE-2026-46623 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 16.1.1

Fixed versions

  • 16.1.1

Solution

Upgrade to version 16.1.1 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-1391: Use of Weak Credentials
  • CWE-620: Unverified Password Change

Source file

maven/org.openidentityplatform.openam/openam-auth-oauth2/CVE-2026-46623.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Mon, 13 Jul 2026 12:20:47 +0000.