CVE-2026-62379
AI description
CVE-2026-62379 is an unauthenticated remote code execution vulnerability found in OpenAM, affecting versions up to and including 16.1.1. The flaw resides within the `AuthXMLUtils.createCustomCallback` method, specifically at the remote authentication endpoint (`/authservice`). This vulnerability allows an attacker to supply an XML element that specifies an arbitrary Java class. The server then loads and instantiates this class without proper validation, enabling the execution of arbitrary code on the server without requiring any prior authentication. The issue has been addressed in OpenAM version 16.1.2.
- Description
- -
- Hype score
- Not currently trending
OpenAMの脆弱性CVE-2026-62379(CVSS 9.8)は認証なしのリモートコード実行を可能にし、CVE-2026-62261はCVSS 9.9のスコアを獲得した OpenAM CVE-2026-62379 (CVSS 9.8) Enables Unauthenticated Remote Code Execution, CVE-2026-62261 Scores CVSS 9.9 #Dai
@foxbook
3 Aug 2026
289 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 OpenAM 16.1.2 patches 4 vulnerabilities, including CVE-2026-62379 (CVSS 9.8), which could allow unauthenticated RCE, and CVE-2026-62261 (CVSS 9.9). No active exploitation or public PoC has been reported. 🔗 https://t.co/uPAHkIzA5a #OpenAM #RCE #CVE #CyberSecurity
@ThreatWire_
1 Aug 2026
739 Impressions
2 Retweets
13 Likes
3 Bookmarks
0 Replies
0 Quotes
Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9. #OpenAM #RCE #IAM #CVE202662379 https://t.co/zjT9OK4mBy
@Daily_CyberSec
31 Jul 2026
491 Impressions
1 Retweet
4 Likes
2 Bookmarks
0 Replies
0 Quotes
OpenAM 16.1.2 fixes 18 vulnerabilities including critical unauthenticated RCE flaws CVE-2026-62379 (CVSS 9.8) and CVE-2026-62263 (CVSS 9.2).
@WorldCyberNewsX
27 Jul 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes