PatchSiren

OpenIdentityPlatform CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL OpenIdentityPlatform CVE published 2026-04-07

CVE-2026-33439

CVE-2026-33439 is a pre-authentication Remote Code Execution (RCE) vulnerability in OpenAM, an access management solution. The vulnerability exists in OpenAM versions prior to 16.0.6 and allows an unauthenticated attacker to achieve arbitrary command execution on the server by sending a crafted serialized Java object as the jato.clientSession GET/POST parameter to any JATO ViewBean endpoint whose JSP cont [truncated]