PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105121 OpenIdentityPlatform CVE debrief

CVE-2026-105121 is an improper authorization vulnerability in OpenAM before 16.1.3 that allows delegated administrators to destroy sessions outside their realms. Authenticated accounts with the iplanet-am-session-destroy-sessions attribute can forcibly log out users in any realm. This issue has a CVSS score of 6.9 and is considered medium severity.

Vendor
OpenIdentityPlatform
Product
OpenAM
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-03
Original CVE updated
2026-10-03
Advisory published
2026-10-03
Advisory updated
2026-10-03

Who should care

Defenders responsible for OpenAM deployments should assess the potential impact of this vulnerability on their systems and verify the presence of this issue in their environment. This includes verifying OpenAM version and configuration to determine exposure and checking authentication configurations that allow session destruction. Security teams and vulnerability management teams should prioritize verifying the presence of this vulnerability in their OpenM

Why it matters

CVE-2026-105121 is a medium-severity vulnerability in OpenAM before 16.1.3 that allows improper authorization for session destruction, potentially impacting user sessions across realms. Defenders should verify the presence of this vulnerability in their deployments and assess potential impact.

  • Verification of OpenAM version and configuration is necessary to determine exposure.
  • Delegated administrators with the iplanet-am-session-destroy-sessions attribute can potentially disrupt user sessions across realms.
  • Defenders should assess authentication configurations that allow session destruction to mitigate potential impact.

Technical summary

The vulnerability exists in OpenAM before 16.1.3, where delegated administrators can destroy sessions outside their realms due to improper authorization checks. This can be exploited by authenticated accounts with the iplanet-am-session-destroy-sessions attribute to forcibly log out users in any realm. Affected product deployments should be verified for exposure. Defenders should assess authentication configurations that allow session destruction to mitigate potential impact. The issue has a CVSS score of 6.9 and is considered medium severity.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their OpenAM deployments and assess the potential impact on their systems.

Recommended defensive actions

  • Verify the presence of this vulnerability in OpenAM deployments
  • Assess the potential impact on systems
  • Check for authentication configurations that allow session destruction
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details about the vulnerability, but do not specify which versions are affected or provide information on exploitation. OpenAM deployments should verify the presence of this vulnerability and assess potential impact. Evidence is limited to CVE and NVD data. Defenders should check for authentication configurations that allow session destruction and verify OpenAM version and configuration to determine exposure.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105121 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105121

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105121 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105121

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-hmwh-9r8r-44gw

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/openam-before-16.1.3-improper-authorization-in-delegated-session-destroy-realm-scoping

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.