PatchSiren cyber security CVE debrief
CVE-2026-105121 OpenIdentityPlatform CVE debrief
CVE-2026-105121 is an improper authorization vulnerability in OpenAM before 16.1.3 that allows delegated administrators to destroy sessions outside their realms. Authenticated accounts with the iplanet-am-session-destroy-sessions attribute can forcibly log out users in any realm. This issue has a CVSS score of 6.9 and is considered medium severity.
- Vendor
- OpenIdentityPlatform
- Product
- OpenAM
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-03
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-03
- Advisory updated
- 2026-10-03
Who should care
Defenders responsible for OpenAM deployments should assess the potential impact of this vulnerability on their systems and verify the presence of this issue in their environment. This includes verifying OpenAM version and configuration to determine exposure and checking authentication configurations that allow session destruction. Security teams and vulnerability management teams should prioritize verifying the presence of this vulnerability in their OpenM
Why it matters
CVE-2026-105121 is a medium-severity vulnerability in OpenAM before 16.1.3 that allows improper authorization for session destruction, potentially impacting user sessions across realms. Defenders should verify the presence of this vulnerability in their deployments and assess potential impact.
- Verification of OpenAM version and configuration is necessary to determine exposure.
- Delegated administrators with the iplanet-am-session-destroy-sessions attribute can potentially disrupt user sessions across realms.
- Defenders should assess authentication configurations that allow session destruction to mitigate potential impact.
Technical summary
The vulnerability exists in OpenAM before 16.1.3, where delegated administrators can destroy sessions outside their realms due to improper authorization checks. This can be exploited by authenticated accounts with the iplanet-am-session-destroy-sessions attribute to forcibly log out users in any realm. Affected product deployments should be verified for exposure. Defenders should assess authentication configurations that allow session destruction to mitigate potential impact. The issue has a CVSS score of 6.9 and is considered medium severity.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their OpenAM deployments and assess the potential impact on their systems.
Recommended defensive actions
- Verify the presence of this vulnerability in OpenAM deployments
- Assess the potential impact on systems
- Check for authentication configurations that allow session destruction
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details about the vulnerability, but do not specify which versions are affected or provide information on exploitation. OpenAM deployments should verify the presence of this vulnerability and assess potential impact. Evidence is limited to CVE and NVD data. Defenders should check for authentication configurations that allow session destruction and verify OpenAM version and configuration to determine exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105121 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105121
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105121 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105121
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-hmwh-9r8r-44gw
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/openam-before-16.1.3-improper-authorization-in-delegated-session-destroy-realm-scoping
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.