CVE-2026-105120
Received Received - Intake

Authorization Bypass in OpenAM Session Query Operation

Vulnerability report for CVE-2026-105120, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: VulnCheck

Description

OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. Attackers holding delegated RealmAdmin privileges can supply a _queryFilter naming another realm to disclose usernames, universal IDs, and session handles across tenant boundaries.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
forgerock openam to 16.1.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in OpenAM versions before 16.1.3. It allows realm administrators with delegated privileges to query sessions across all realms by supplying a crafted _queryFilter parameter specifying another realm. This exposes usernames, universal IDs, and session handles across tenant boundaries.

Detection Guidance

Monitor OpenAM session query endpoints for unusual activity, such as GET requests to /json/{realm}/sessions with _queryFilter parameters specifying other realms. Check audit logs for unauthorized access attempts or excessive session queries across multiple realms.

Impact Analysis

Attackers with RealmAdmin privileges can exploit this to disclose sensitive session information across realms. This enables user enumeration, targeted attacks, and potential violation of tenant boundaries. The vulnerability supports unauthorized access to usernames, universal IDs, realms, session handles, and session times.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and privacy regulations such as GDPR and HIPAA. It enables unauthorized exposure of sensitive session data across tenant boundaries, which could constitute a data breach under these standards.

Mitigation Strategies

Upgrade OpenAM to version 16.1.3 or later to patch the vulnerability. Restrict delegated administrator privileges to prevent unauthorized realm access. Implement network-level restrictions to block unauthorized session queries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105120. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart