CVE-2026-46498
Received Received - Intake

OAuth Token Forgery in OpenAM via CTS Manipulation

Vulnerability report for CVE-2026-46498, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: GitHub, Inc.

Description

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied token identifiers from the shared Core Token Store (CTS) without an OAuth-only namespace, and OAuthAdapter accepts a row whose BLOB claims to contain an OAuth token without binding the trusted CTS type or verifying integrity. An attacker who can place controlled JSON in CTS under a known token identifier, such as through Push Registration followed by an anonymous SNS callback in an enabled realm, can mint OAuth bearer tokens and OpenID Connect ID tokens with chosen subject, client, realm, and scope. The flaw does not by itself create an OpenAM SSO session or grant console access. This issue is fixed in version 16.1.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
forgerock openam 16.1.1
openidentityplatform openam 16.1.1
openidentityplatform openam to 16.0.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-46498 is a flaw in OpenAM, an access management solution, where OAuth token identifiers are read from the Core Token Store without proper namespace isolation or integrity checks. This allows attackers to mint valid OAuth bearer tokens and OpenID Connect ID tokens with chosen attributes by placing controlled JSON in the CTS under a known token identifier.

Impact Analysis

An attacker could forge OAuth2 tokens with arbitrary subject, client, realm, and scope values. This could allow unauthorized access to protected resources or impersonation of users. The flaw does not create an OpenAM SSO session or grant console access but enables token-based attacks.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Forged tokens may allow attackers to bypass authentication, potentially exposing personal or health information, leading to compliance breaches and regulatory penalties.

Mitigation Strategies

Upgrade OpenAM to version 16.1.1 or later to address the vulnerability in OAuth token handling and prevent arbitrary token minting.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-46498. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart