CVE-2026-44202MEDIUMCVSS 0.0

OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice`

Published Jun 22, 2026·Updated Jun 22, 2026

Description

OpenAM (Open Identity Platform) is an open-source Identity and Access Management (IAM) platform derived from ForgeRock OpenAM, providing SSO, OAuth2, SAML, and OpenID Connect capabilities. It is widely deployed in enterprise environments as a central authentication gateway. The `/sessionservice` endpoint, used for internal session management operations, does not sufficiently restrict the URLs that authenticated users may register for session event notifications. Under certain conditions, this may result in outbound server-side requests to attacker-controlled destinations, potentially exposing session-related data. This behavior results in a **server-side request forgery (SSRF)** vulnerability, where an authenticated attacker can trigger outbound requests to arbitrary destinations. ## Credit Discovered by **JD-Security SHENYI Team**

Affected Packages (1)

org.openidentityplatform.openam:openam-coreMAVEN
Fixed in = 16.0.6

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free