CVE-2026-47424
Received Received - Intake

Groovy Sandbox Escape in OpenAM

Vulnerability report for CVE-2026-47424, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: GitHub, Inc.

Description

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated server-side script author to escape the scripting sandbox despite the default class allow and deny lists. A user such as a sub-realm RealmAdmin who can create or edit a script in an executed context can invoke operating-system commands as the OpenAM application server account, crossing the realm-scoped administration boundary and compromising the JVM and every realm it serves. This issue is fixed in version 16.1.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
forgerock openam 16.1.1
openidentityplatform openam 16.1.1
openidentityplatform openam to 16.0.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-693 The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-47424 is a high-severity vulnerability in OpenAM, an access management solution. It involves a flaw in the GroovySandboxValueFilter component that allows authenticated script authors to escape the scripting sandbox. This enables them to execute operating-system commands as the OpenAM application server account, compromising the entire OpenAM process and all realms it serves.

Detection Guidance

To detect this vulnerability, check the OpenAM version installed on your system. If it is 16.0.6 or earlier, the system is vulnerable. Run commands like 'find / -name openam' or check the version via the OpenAM admin console or server logs.

Impact Analysis

An attacker with the ability to create or edit server-side scripts, such as a realm admin, can exploit this flaw to run arbitrary OS commands with the privileges of the OpenAM application server admin. This could lead to full system compromise, data breaches, or unauthorized access to sensitive information.

Mitigation Strategies

Immediately upgrade OpenAM to version 16.1.1 or later to patch the vulnerability. If upgrading is not possible, restrict access to script creation and editing features for all users, especially realm admins, to reduce attack surface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47424. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart