CVE-2026-45048: OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC
Description
An insufficient authorization (CWE-285) and information exposure (CWE-200) issue in OpenAM’s session management endpoint allows a low-privileged authenticated user to retrieve active session credentials belonging to other users, including those with higher privileges. This affects OpenAM Community Edition through version 16.0.6 and was patched in version 16.1.1.
This may be related to CVE-2021-4201, a similar issue patched in ForgeRock Access Management, a separate product sharing a common codebase ancestry.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-45048 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →