OPENAM 16.1.2 patched four critical security flaws, including CVE-2026-62379, which allows unauthenticated remote code execution (RCE) with a CVSS score of 9.8. This vulnerability can lead to full server compromise. OpenAM is essential for authentication and authorization across various applications. Two other vulnerabilities also allow RCE with authentication. The flaws include: CVE-2026-62261 (script execution risk) and CVE-2026-62263 (pre-authentication deserialization flaw). Affected versions are prior to 16.1.2, and immediate upgrade is recommended as well as interim security measures.
OpenAM CVE-2026-62379 (CVSS 9.8) Enables Unauthenticated Remote Code Execution, CVE-2026-62261 Scores CVSS 9.9
CyberSIXT Evidence Panel
Article by CyberSIXT