{"id":"GHSA-wg5r-wc3x-39vc","summary":"OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback","details":"## Summary\nA pre-authentication remote code execution vulnerability affects OpenAM. The\nremote authentication endpoint (`/authservice`, PLL) accepts an XML element\nthat names an arbitrary Java class, which the server then loads and\ninstantiates without validation. On a default configuration this is reachable\n**without authentication** and allows an attacker to run code on the server.\n\n## Impact\nUnauthenticated remote code execution / full server compromise on any OpenAM\ninstance with default settings.\n\n## Affected\nAll releases up to and including 16.1.1 (the defect predates the Open Identity\nPlatform fork).\n\n## Remediation\nUpgrade to `16.1.2`. The fix resolves the class named in a `\u003cCustomCallback\u003e`\nelement without running its static initialisers and rejects it unless it\nimplements `DSAMECallbackInterface`, and it constrains deserialisation of the\nserialised `Subject` value to a class allowlist.\n\n## Interim mitigation\nIf you cannot upgrade immediately:\n\n- **Restrict or block external network access to `/authservice`.** This is the\n  only reliable mitigation.\n- Optionally, **block PLL requests carrying a `\u003cCustomCallback className=\"...\"\u003e`\n  element** at the reverse proxy or WAF. That element is only produced for custom\n  `DSAMECallbackInterface` callbacks, so most deployments never send it — confirm\n  against your own traffic before enforcing.\n- **Enabling `sunRemoteAuthSecurityEnabled` does *not* mitigate this issue.** The\n  remote-auth security token is checked in `AuthXMLHandler.processAuthXMLRequest`,\n  which runs only after `AuthXMLRequest.parseXML` has already parsed the request\n  and instantiated the class named in the `\u003cCustomCallback className=\"...\"\u003e`\n  element. Do not rely on it as a substitute for upgrading or for network\n  restriction.\n\n## Credit\nVulnerability discovered by Zhixi \"Jace\" Sun of ASM/VI at TikTok.\nCorrection of the interim mitigation guidance contributed by @BarakSrour.","aliases":["CVE-2026-62379"],"modified":"2026-08-18T05:15:07.603071164Z","published":"2026-07-24T21:11:09Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-07-24T21:11:09Z","nvd_published_at":null,"cwe_ids":["CWE-470","CWE-94"]},"references":[{"type":"WEB","url":"https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-wg5r-wc3x-39vc"},{"type":"WEB","url":"https://github.com/OpenIdentityPlatform/OpenAM/commit/edcf968cad91a78b932dba4ad559ef94cbf35f5a"},{"type":"PACKAGE","url":"https://github.com/OpenIdentityPlatform/OpenAM"},{"type":"WEB","url":"https://github.com/OpenIdentityPlatform/OpenAM/releases/tag/16.1.2"}],"affected":[{"package":{"name":"org.openidentityplatform.openam:openam-core","ecosystem":"Maven","purl":"pkg:maven/org.openidentityplatform.openam/openam-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"16.1.2"}]}],"versions":["14.5.2","14.5.3","14.5.4","14.6.1","14.6.2","14.6.3","14.6.4","14.6.5","14.6.6","14.7.0","14.7.1","14.7.2","14.7.3","14.7.4","14.8.1","14.8.2","14.8.3","14.8.4","15.0.0","15.0.1","15.0.2","15.0.3","15.0.4","15.1.0","15.1.1","15.1.2","15.1.3","15.1.4","15.1.5","15.1.6","15.2.0","15.2.1","15.2.2","16.0.1","16.0.2","16.0.3","16.0.4","16.0.5","16.0.6","16.1.0","16.1.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 16.1.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-wg5r-wc3x-39vc/GHSA-wg5r-wc3x-39vc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}