CVE-2026-105121 - OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping
CVE ID :CVE-2026-105121
Published : Oct. 3, 2026, 2:16 p.m. | 2 hours, 57 minutes ago
Description :OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 3, 2026, 2:16 p.m. | 2 hours, 57 minutes ago
Description :OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...