External risk intelligence

OpenAM WebAuthn Deserialization Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-45051

OpenAM is an access management and identity solution typically deployed as an internet-facing gateway or service to handle authentication flows. While the vulnerability requires specific configuration and data manipulation to reach the deserialization point, the product itself is designed to be reachable at the network edge.

Deserialization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in the Open Access Management solution, specifically within its WebAuthn authentication process. If certain conditions are met, including an attacker's ability to control specific user attributes, a flaw in how data is handled could allow for the execution of malicious code within the application server. The primary concern is to confirm if our deployed instances of this technology are affected and to what extent.

  • Malicious code execution via data deserialization.
  • Affects a critical access management component.
  • Confirm relevance and exposure to this threat.

Attack Path

How an attacker could exploit the issue

An attacker could compromise an OpenAM server by manipulating user attributes, which are then deserialized without proper filtering during the WebAuthn authentication process. This occurs when an attacker can write controlled data to a user attribute, such as through delegated administration or directory access, before the system verifies the WebAuthn assertion. Successful exploitation allows the attacker to execute arbitrary code within the application server's process.

  • Requires attacker-controlled data in user attributes.
  • Triggered by WebAuthn flow deserializing data.
  • Risk of arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to execute arbitrary code on the application server when a serialized object is loaded without proper filtering. This might occur if an attacker can first control data written to a user attribute through various administrative or provisioning interfaces, and then trigger the WebAuthn authentication flow. The impact is limited to conditions where the WebAuthn flow is reachable and controlled data can be pre-written to the attribute.

  • Application server code execution.
  • Unfiltered deserialization of controlled data.
  • Compromise of application server.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world ownership for this vulnerability likely involves application owners responsible for the OpenAM deployment, potentially in collaboration with infrastructure or platform teams managing the application servers. The first practical step is to identify all instances of OpenAM, confirm their reachability and business criticality, and then determine the specific owner for each instance to prioritize remediation.

  • Application owners to manage remediation efforts.
  • Verify reachability and business criticality first.
  • Plan for vendor coordination and updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Open Access Management (OpenAM)?

OpenAM is a software solution designed to manage digital identities and access control. Organizations typically use it as a central gateway to verify user identities and regulate access to applications and services, acting as a critical point of authentication in a network architecture.

What is the vulnerability in CVE-2026-45051?

This CVE involves a security weakness known as Deserialization of Untrusted Data (CWE-502). It occurs when the software reconstructs data into objects without sufficient validation. Because this happens during the WebAuthn authentication flow, an attacker could potentially trick the application server into executing harmful code embedded within that data.

How is this vulnerability triggered?

An attacker must first manage to store malicious data inside a user attribute via channels like directory access or self-registration. If the WebAuthn flow is then accessed, the system deserializes that stored data. The vulnerability does not trigger if the attacker cannot control those specific user attributes or if the WebAuthn flow remains unused.

Why does Halo Surface Signal categorize this as external?

Halo Surface Signal flags this as likely relevant because OpenAM is often deployed at the network edge to manage authentication for users. Since this product is frequently configured to be internet-facing to support remote access, the potential for an attacker to reach the vulnerable WebAuthn flow is higher than for internal-only services.

What are the first steps for someone running OpenAM?

Begin by auditing your environment to locate all active instances of OpenAM. Determine which versions are currently in use, as the vulnerability affects versions prior to 16.1.1. Once identified, consult your internal application owners to coordinate the necessary updates provided by the vendor to resolve the flaw.

References