CVE-2026-45049: OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet
Description
An Information Exposure Through Sent Data (CWE-201) issue in OpenAM’s Cross-Domain Single Sign-On (CDSSO) servlet allows a logged-in user’s raw OpenAM session token to be POSTed to an attacker-controlled URL. This impacts OpenAM Community Edition through version 16.0.6. This issue was patched in version 16.1.1.
An attacker who can induce a logged-in victim to visit a crafted URL may receive the victim’s session credential, which could enable session hijacking.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-45049 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →