CVE-2026-44202

Source
https://cve.org/CVERecord?id=CVE-2026-44202
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44202.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-44202
Aliases
Downstream
Published
2026-09-15T09:47:00Z
Modified
2026-09-27T08:04:13Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N CVSS Calculator
Summary
OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice`
Details

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbitrary notification URL without requiring an administrative or application client token. SessionRequestHandler passes the attacker-controlled destination to the session listener service, causing the OpenAM server to make outbound requests and potentially disclose session-related notification data to an attacker-controlled destination. This issue is fixed in version 16.1.1.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44202.json"
}
References

Affected packages

Git / github.com/openidentityplatform/openam

Affected ranges

Type
GIT
Repo
https://github.com/openidentityplatform/openam
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "16.1.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

13.*
13.0.0
13.0.0-RC1
13.0.0-RC10
13.0.0-RC2
13.0.0-RC3
13.0.0-RC4
13.0.0-RC5
13.0.0-RC6
13.0.0-RC7
13.0.0-RC8
13.0.0-RC9
14.*
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.0.5
14.0.6
14.1.1
14.1.10
14.1.11
14.1.12
14.1.13
14.1.16
14.1.17
14.1.2
14.1.3
14.1.4
14.1.5
14.1.6
14.1.7
14.1.8
14.1.9
14.2.1
14.2.2
14.3.1
14.4.1
14.4.2
14.5.1
14.5.2
14.5.3
14.5.4
14.6.2
14.6.3
14.6.4
14.6.5
14.6.6
14.7.0
14.7.1
14.7.2
14.7.3
14.7.4
14.8.1
14.8.2
14.8.3
14.8.4
15.*
15.0.0
15.0.1
15.0.2
15.0.3
15.0.4
15.1.0
15.1.1
15.1.2
15.1.3
15.1.4
15.1.5
15.1.6
15.2.0
15.2.1
15.2.2
16.*
16.0.3
16.0.4
16.0.5
16.0.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44202.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "263558722275762346258973936100290117723",
                "298569964518128227914754048219273218116",
                "119059167908144391336245310009902302207",
                "289523359191662634909993211093372826570"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-44202-04dc8fb8",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/openidentityplatform/openam/commit/a13a4b63ae0e0670c63cbcfa79586407408b3920",
        "target": {
            "file": "openam-core/src/main/java/com/iplanet/dpro/session/operations/strategies/StatelessOperations.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "72478005795875493944172599283621993754",
                "77076995860774334291649112210329774100",
                "132870654259325284251116698059873197465",
                "178067351594357630857502771361512354526",
                "70697164901857956332447546585366737454",
                "158310028964326889378021628499923253258",
                "8046690135120716365181788286521837529",
                "62320678491593089755875025471347754669",
                "194779627086642436846324194611852054543",
                "245173442220350232782273655595729551036",
                "211124750741346702556342679221296147398",
                "51193539170301659547477532710753757331",
                "243776250436196968873353957451761361509",
                "121706726922920503114021444483150432894",
                "163673298573750618117317406951424497925",
                "13395505329060772986247273224008421721",
                "214013363595931639113524509380839169020",
                "37027377111310790177772623805543778580",
                "111265490651965797492789524425938437557"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-44202-15283064",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/openidentityplatform/openam/commit/a13a4b63ae0e0670c63cbcfa79586407408b3920",
        "target": {
            "file": "openam-core/src/main/java/com/iplanet/dpro/session/Session.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "109186641582198437338252314897349696549",
                "46106833086357709313286339415101063106",
                "190960166832474617620534573803997616113",
                "277475151426367635083822366302527564833",
                "124516232544374307750485297263874861586",
                "39280857588192899026527004650331494024"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-44202-21436c94",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/openidentityplatform/openam/commit/a13a4b63ae0e0670c63cbcfa79586407408b3920",
        "target": {
            "file": "openam-core/src/main/java/com/iplanet/dpro/session/service/SessionService.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "27955558668625781381609990079956454721",
            "length": 164
        },
        "id": "CVE-2026-44202-32ce8e74",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/openidentityplatform/openam/commit/a13a4b63ae0e0670c63cbcfa79586407408b3920",
        "target": {
            "file": "openam-core/src/main/java/com/iplanet/dpro/session/service/SessionService.java",
            "function": "addSessionListener"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "121278473081629437326577476282383708347",
                "101998531957453354705577472519347757950",
                "195708975104041607382476688398135715749",
                "235704037218139552329883006385311728757",
                "264871076941777657039330607664654321284",
                "247830832478557257147130159480265421475",
                "162028818125505930170285182827663931077",
                "229168178198946036229032011673521425788",
                "269529051059733898147918436659191270278",
                "7231156408230777597877588867796615373",
                "256749120660405223373990970503302710769",
                "318206726293862692450177716636913551894",
                "146039096336620267879926686821236035337"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-44202-37659a8d",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/openidentityplatform/openam/commit/a13a4b63ae0e0670c63cbcfa79586407408b3920",
        "target": {
            "file": "openam-core/src/main/java/com/iplanet/dpro/session/operations/strategies/LocalOperations.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "68405393574969697471038927108477541145",
            "length": 1715
        },
        "id": "CVE-2026-44202-43232f28",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/openidentityplatform/openam/commit/a13a4b63ae0e0670c63cbcfa79586407408b3920",
        "target": {
            "file": "openam-core/src/main/java/com/iplanet/dpro/session/service/SessionRequestHandler.java",
            "function": "processMethod"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "79805275620397555450877316545485885447",
                "127500050811209219570555750970821350511",
                "134202947025155162196370768396496966238",
                "280468017051491376934783846935192619245",
                "210748444671904703518436364471617082016",
                "179971330916687693100278913629572243902"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-44202-46a31cb1",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/openidentityplatform/openam/commit/a13a4b63ae0e0670c63cbcfa79586407408b3920",
        "target": {
            "file": "openam-core/src/main/java/com/iplanet/dpro/session/monitoring/MonitoredOperations.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "260009109631030635683801150931336915539",
                "334595090758857944393479325288194400900",
                "257799116536833724492481101274321672043",
                "111132934953768225054294783817992420898",
                "290521086778719965801877065536634901988"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-44202-70b7aecb",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/openidentityplatform/openam/commit/a13a4b63ae0e0670c63cbcfa79586407408b3920",
        "target": {
            "file": "openam-core/src/main/java/com/iplanet/dpro/session/operations/strategies/ClientSdkOperations.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "328778035869048333639789190494324132347",
                "25054378421003210797861807434534004785",
                "270599848572587088516085955037506717986",
                "6399077579866260272222857721529807322",
                "321387532576288672433808253218635858924"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-44202-8164503f",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/openidentityplatform/openam/commit/a13a4b63ae0e0670c63cbcfa79586407408b3920",
        "target": {
            "file": "openam-core/src/main/java/com/iplanet/dpro/session/operations/SessionOperations.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "89386096222319442624933857939103787935",
            "length": 284
        },
        "id": "CVE-2026-44202-8e6aee38",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/openidentityplatform/openam/commit/a13a4b63ae0e0670c63cbcfa79586407408b3920",
        "target": {
            "file": "openam-core/src/main/java/com/iplanet/dpro/session/Session.java",
            "function": "addInternalSessionListener"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "261865358264818051568288550700116285621",
                "157391822943326260623914450207598164150",
                "313009451500916968615809691964789492235",
                "59968852037580017647312884660265172263",
                "69762279680502554719218587245200556745"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-44202-b651eb13",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/openidentityplatform/openam/commit/a13a4b63ae0e0670c63cbcfa79586407408b3920",
        "target": {
            "file": "openam-core/src/main/java/com/iplanet/dpro/session/service/SessionRequestHandler.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "162356134715387055700272023212026807386",
            "length": 433
        },
        "id": "CVE-2026-44202-d2492086",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/openidentityplatform/openam/commit/a13a4b63ae0e0670c63cbcfa79586407408b3920",
        "target": {
            "file": "openam-core/src/main/java/com/iplanet/dpro/session/operations/strategies/LocalOperations.java",
            "function": "addSessionListener"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "239345723765152436646767487403757992122",
            "length": 121
        },
        "id": "CVE-2026-44202-e0afe3e0",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/openidentityplatform/openam/commit/a13a4b63ae0e0670c63cbcfa79586407408b3920",
        "target": {
            "file": "openam-core/src/main/java/com/iplanet/dpro/session/monitoring/MonitoredOperations.java",
            "function": "addSessionListener"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "102608968260706350217908711297223212188",
            "length": 317
        },
        "id": "CVE-2026-44202-fc0256c2",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/openidentityplatform/openam/commit/a13a4b63ae0e0670c63cbcfa79586407408b3920",
        "target": {
            "file": "openam-core/src/main/java/com/iplanet/dpro/session/operations/strategies/ClientSdkOperations.java",
            "function": "addSessionListener"
        }
    }
]
vanir_signatures_modified
"2026-09-27T08:04:13Z"