CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-45051

unknowncovered by 1 sourcefirst seen 2026-09-15
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators without an ObjectInputFilter. Exploitation requires the WebAuthn flow to be reachable and an attacker to have previously written controlled data to that attribute through delegated administration, provisioning, directory access, legacy REST self-registration, or unsafe configuration. When those non-default conditions hold, the data is deserialized before assertion verification and can execute a classpath gadget in the application server process. This issue is fixed in version 16.1.1.

⚡ Watch CVE-2026-45051

Get an email if CVE-2026-45051 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-45051

CVE.org record

Embed the live status

CVE-2026-45051 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-45051 status](https://www.csirts.com/badge/CVE-2026-45051)](https://www.csirts.com/cve/CVE-2026-45051)