GHSA-wg5r-wc3x-39vc: OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
Summary
A pre-authentication remote code execution vulnerability affects OpenAM. The
remote authentication endpoint (/authservice, PLL) accepts an XML element
that names an arbitrary Java class, which the server then loads and
instantiates without validation. On a default configuration this is reachable
without authentication and allows an attacker to run code on the server.
Impact
Unauthenticated remote code execution / full server compromise on any OpenAM
instance with default settings.
Affected
All releases up to and including 16.1.1 (the defect predates the Open Identity
Platform fork).
Remediation
Upgrade to 16.1.2.
Interim mitigation
- Require the remote-auth security token by enabling
sunRemoteAuthSecurityEnabled (rejects unauthenticated /authservice calls).
- Restrict or block external network access to /authservice until patched.
Credit
Vulnerability discovered by Zhixi "Jace" Sun of ASM/VI at TikTok.
Details
Original advisory: https://github.com/advisories/GHSA-wg5r-wc3x-39vc
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-62379 | coverage & exploitation status | NVD · CVE.org |
More from GitHub Security Advisories
- mediumGHSA-jr6p-8pjj-mfx6: Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators s…2026-07-31
- mediumGHSA-68cj-mvg9-rgm2: Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing…2026-07-31
- mediumGHSA-ff84-5f28-78qj: re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex`…2026-07-31
- mediumGHSA-6hxr-mr5r-9836: re2: Global `String.prototype.match` with an empty-matchable pattern never advances → inf…2026-07-31
- mediumGHSA-x83g-979r-f5fh: Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII2026-07-31