Authorization Bypass Through User-Controlled Key Affecting org.openidentityplatform.openam:openam-oauth2 package, versions [,16.1.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Authorization Bypass Through User-Controlled Key vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGOPENIDENTITYPLATFORMOPENAM-17675302
  • published29 Jun 2026
  • disclosed25 Jun 2026
  • creditUnknown

Introduced: 25 Jun 2026

NewCVE-2026-46498  (opens in a new tab)
CWE-639  (opens in a new tab)

How to fix?

Upgrade org.openidentityplatform.openam:openam-oauth2 to version 16.1.1 or higher.

Overview

Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key in the token-read process. An attacker can generate unauthorized OAuth2 bearer tokens with arbitrary user, client, realm, and scope values by injecting attacker-controlled JSON into the shared Core Token Store under a known identifier. This is only exploitable if the OAuth2 Provider service is enabled in a realm and the attacker can register a push notification, allowing them to trigger the vulnerable path.

CVSS Base Scores

version 4.0
version 3.1