Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not enforce ownership or privilege checks when a low-privileged authenticated user queries session information in deployments using stateful session storage. A requester who knows a target identity identifier can retrieve another user's active session credentials, including credentials for a more privileged account, and use them to hijack that session. This issue is fixed in version 16.1.1.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-200",
"CWE-285"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45048.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "16.1.1"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45048.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"313209565118702977782415891441222364593",
"126335014874355697869946523607113822020",
"110297713027250277294276525585728122530",
"308576734144223189738326005562876973656",
"266284031377182680636545126208153047467",
"44274504888863571869145466147432568410",
"25005256176653971101545014578875120912",
"320643328230886238927652530085619949691",
"127141438584299456007128176578546937126",
"87796099884361563697653026091755078302",
"142673961109733917749738868342527397860",
"130892054177880824492780035541371138337",
"171083797192488059572100155321724695520",
"7683545040232968657228075259184840911",
"59685938215984952314998241825010833835"
],
"threshold": 0.9
},
"id": "CVE-2026-45048-06258e39",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openidentityplatform/openam/commit/f775b42236b3cb94e3a02a19f4a4f4f5cc0b91c4",
"target": {
"file": "openam-core/src/main/java/com/iplanet/dpro/session/service/SessionRequestHandler.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "107997978314294852383595147123389669806",
"length": 1174
},
"id": "CVE-2026-45048-5c3ba24a",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openidentityplatform/openam/commit/f775b42236b3cb94e3a02a19f4a4f4f5cc0b91c4",
"target": {
"file": "openam-core/src/main/java/com/iplanet/dpro/session/service/SessionRequestHandler.java",
"function": "verifyValidRequest"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "193332595533865999079962874425405619031",
"length": 1736
},
"id": "CVE-2026-45048-7c5c609f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openidentityplatform/openam/commit/f775b42236b3cb94e3a02a19f4a4f4f5cc0b91c4",
"target": {
"file": "openam-core/src/main/java/com/iplanet/dpro/session/service/SessionRequestHandler.java",
"function": "processMethod"
}
}
]
"2026-09-18T08:10:17Z"