Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') Affecting org.openidentityplatform.openam:openam-core package, versions [,16.1.2)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGOPENIDENTITYPLATFORMOPENAM-18313060
  • published26 Jul 2026
  • disclosed24 Jul 2026
  • creditmanus-use

Introduced: 24 Jul 2026

NewCVE-2026-62379  (opens in a new tab)
CWE-470  (opens in a new tab)
CWE-94  (opens in a new tab)

How to fix?

Upgrade org.openidentityplatform.openam:openam-core to version 16.1.2 or higher.

Overview

Affected versions of this package are vulnerable to Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') via the AuthXMLUtils.createCustomCallback process. An attacker can execute arbitrary code on the server by sending a crafted XML element to the /authservice endpoint that specifies an arbitrary Java class to be loaded and instantiated. This is only exploitable if the default configuration is used and the sunRemoteAuthSecurityEnabled setting is not enabled.

Workaround

This vulnerability can be mitigated by enabling the sunRemoteAuthSecurityEnabled setting to require a remote-auth security token, or by restricting or blocking external network access to the /authservice endpoint.

CVSS Base Scores

version 4.0
version 3.1