OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 03 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm. | |
| Title | OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping | |
| First Time appeared |
Openidentityplatform
Openidentityplatform openam |
|
| Weaknesses | CWE-285 | |
| CPEs | cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openidentityplatform
Openidentityplatform openam |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-03T12:14:44.905Z
Reserved: 2026-10-03T12:04:36.964Z
Link: CVE-2026-105121
No data.
Status : Received
Published: 2026-10-03T14:16:38.997
Modified: 2026-10-03T14:16:38.997
Link: CVE-2026-105121
No data.
OpenCVE Enrichment
Updated: 2026-10-03T15:30:19Z
Weaknesses