PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-44793 OpenIdentityPlatform CVE debrief

CVE-2026-44793 is a high-severity vulnerability in Open Access Management (OpenAM) that allows an unauthenticated attacker to execute script in the OpenAM origin by inducing a user to follow a crafted request. The issue is fixed in version 16.1.1. This vulnerability affects OpenAM deployments in non-default clustered configurations. Defenders should assess exposure and prioritize patching to prevent potential script execution. The vulnerability is caused by inconsistent encoding of user-supplied parameters in the SAML2 cluster cookie-hash redirect path.

Vendor
OpenIdentityPlatform
Product
OpenAM
CVSS
HIGH 7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-23
Advisory published
2026-09-15
Advisory updated
2026-09-23

Who should care

Defenders responsible for OpenAM deployments should assess exposure and prioritize patching to prevent potential script execution. OpenAM administrators, security teams, and vulnerability management teams should review the CVE record and NVD entry to understand the vulnerability and its impact. Additionally, operators and platform teams should be aware of the potential risk and take necessary actions to mitigate it.

Why it matters

CVE-2026-44793 is a high-severity vulnerability in OpenAM that allows script execution. Defenders should prioritize patching OpenAM instances to prevent potential impact.

  • Potential script execution in OpenAM origin
  • Unauthenticated attacker can induce user to follow crafted request
  • Patching OpenAM instances to version 16.1.1 is recommended

Technical summary

CVE-2026-44793 is a high-severity vulnerability in Open Access Management (OpenAM) that allows an unauthenticated attacker to execute script in the OpenAM origin by inducing a user to follow a crafted request. The issue is fixed in version 16.1.1. The vulnerability is caused by inconsistent encoding of user-supplied parameters in the SAML2 cluster cookie-hash redirect path. This issue affects OpenAM deployments in non-default clustered configurations. Defenders should prioritize patching OpenAM instances to prevent potential script execution.

Defensive priority

Defenders should prioritize patching OpenAM instances to prevent potential script execution.

Recommended defensive actions

  • Patch OpenAM instances to version 16.1.1
  • Review and update OpenAM configurations to ensure secure deployment
  • Monitor OpenAM instances for potential suspicious activity
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional information on affected versions and potential impact is limited. OpenAM deployments should be reviewed for exposure, and defenders should verify the patching status of their OpenAM instances. The CVE record was published on 2026-09-15T10:17:03.717Z and has not been modified since then. No additional information is available on potential exploit attempts or affected organizations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-44793 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-44793

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-44793 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44793

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.