CVE-2026-33439
Open Access Management (OpenAM) versions prior to 16.0.6 contain a pre‑authentication remote code execution flaw caused by unsafe Java deserialization of the jato.clientSession HTTP parameter. An unauthenticated attacker can send a crafted serialized object to any JATO ViewBean endpoint that uses <jato:form> tags (e.g., password reset pages) and achieve arbitrary command execution on the server. The issue is resolved in OpenAM 16.0.6.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
OpenIdentityPlatform OpenAM
Real-world impact
Arbitrary command execution on the server with no authentication required.
Why this severity
CVSS v4.0 base score 9.3 (Critical) due to network‑adjacent, low‑complexity attack with high impact on confidentiality, integrity, and availability.
What to do about it
- 01Upgrade OpenAM to version 16.0.6 or later.
NVD-referenced vendor advisory
Timeline
- Apr 7, 2026 · Apr 7, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/OpenIdentityPlatform/OpenAM…exploitvendor advisory