CVE-2026-62379

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-62379 is an unauthenticated remote code execution vulnerability found in OpenAM, affecting versions up to and including 16.1.1. The flaw resides within the `AuthXMLUtils.createCustomCallback` method, specifically at the remote authentication endpoint (`/authservice`). This vulnerability allows an attacker to supply an XML element that specifies an arbitrary Java class. The server then loads and instantiates this class without proper validation, enabling the execution of arbitrary code on the server without requiring any prior authentication. The issue has been addressed in OpenAM version 16.1.2.

Description
-

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.