SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-45048

HIGH · CVSS 8.5 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

OpenAM's SessionRequestHandler prior to version 16.1.1 is vulnerable due to a lack of ownership and privilege checks, allowing low-privileged authenticated users to access and retrieve active session credentials of other users, including those with higher privileges. This flaw can lead to session hijacking, posing a significant risk to user accounts and sensitive data. Organizations using affected versions of OpenAM should prioritize upgrading to version 16.1.1 to mitigate this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-45048
Severity
HIGH
CVSS
8.5
EPSS
0.25%

Original NVD Description

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not enforce ownership or privilege checks when a low-privileged authenticated user queries session information in deployments using stateful session storage. A requester who knows a target identity identifier can retrieve another user's active session credentials, including credentials for a more privileged account, and use them to hijack that session. This issue is fixed in version 16.1.1.