CVE-2026-33439Disclosure(openidentityplatform / openam)

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch openidentityplatform openam systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP parameter. This bypasses the WhitelistObjectInputStream mitigation that was applied to the jato.pageSession parameter after CVE-2021-35464. An unauthenticated attacker can achieve arbitrary command execution on the server by sending a crafted serialized Java object as the jato.clientSession GET/POST parameter to any JATO ViewBean endpoint whose JSP contains <jato:form> tags (e.g., the Password Reset pages). This vulnerability is fixed in 16.0.6.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openam

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 17 mentions across 13 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 16 signals
  • Disclosure: 11 classified signals
  • Peaked 11d ago at 3 mentions (2026-04-08); latest day: 1
  • 17 total mentions across 13 days

Affected systems

Products
openam

Deep dive

Activity timeline17 mentions / 13d
01223Mentions · 2026-04-07: 1Mentions · 2026-04-08: 3Mentions · 2026-04-09: 2Mentions · 2026-04-12: 1Mentions · 2026-04-13: 1Mentions · 2026-04-17: 2Mentions · 2026-05-11: 1Mentions · 2026-05-13: 1Mentions · 2026-05-27: 1Mentions · 2026-06-24: 1Mentions · 2026-09-13: 1Mentions · 2026-09-18: 1Mentions · 2026-09-20: 1PoC Mentioned / Linked · 2026-04-07: 1PoC Mentioned / Linked · 2026-04-08: 1PoC Mentioned / Linked · 2026-04-09: 1PoC Mentioned / Linked · 2026-05-13: 1PoC Mentioned / Linked · 2026-09-13: 1PoC Mentioned / Linked · 2026-09-18: 1Exploit Tool / Code · 2026-09-13: 1Exploit Tool / Code · 2026-09-18: 1Active Exploitation · 2026-04-13: 1Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-17: 1Patch / Workaround · 2026-05-13: 1Technical Details · 2026-04-07: 1Technical Details · 2026-04-08: 3Technical Details · 2026-04-09: 2Technical Details · 2026-04-12: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-17: 2Technical Details · 2026-05-11: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-27: 1Technical Details · 2026-09-13: 1Technical Details · 2026-09-18: 1Technical Details · 2026-09-20: 104-0704-0804-0904-1204-1304-1705-1105-1305-2706-2409-1309-1809-20
Signal classification5 categories
Disclosure
1164.7%
Patch
211.8%
Exploit
211.8%
General
15.9%
Active Exploitation
15.9%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-04-071
Disclosure1
2026-04-083
Disclosure2General1
2026-04-092
Disclosure1Patch1
2026-04-121
Disclosure1
2026-04-131
Active Exploitation1
2026-04-172
Disclosure1Patch1
2026-05-111
Disclosure1
2026-05-131
Disclosure1
2026-05-271
Disclosure1
2026-06-241
Disclosure1
2026-09-131
Exploit1
2026-09-181
Exploit1
2026-09-201
Disclosure1
Full discourse17 posts
  • Hacktron AI@HacktronAI
    Disclosure

    As part of our efforts in securing open source, here's our latest finding: Pre-Auth RCE in OpenAM via jato.clientSession (CVE-2026-33439) https://www.hacktron.ai/blog/openam-deserialization-pre-auth-rce https://t.co/dQ30bq7aFR

    Post summary

    This tweet announces the discovery of a Pre‑Auth RCE in OpenAM via jato.clientSession (CVE‑2026‑33439) and links to a blog post that likely contains further details or a PoC.

    216064124.9K
    3.9K followersView on X
  • Ryx@PadhiyarRushi
    Exploit

    OpenAM pre-auth RCE PoC is out (CVE-2026-33439). Standalone Python exploit for jato.clientSession deserialization. Sends a command via HTTP header and returns output in the response. No extra dependencies required. https://sploitus.com/exploit?id=B2C95D2F-FF4C-5818-8899-798371B683D2 #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #RCE #AppSec

    Post summary

    The post announces a PoC for an OpenAM pre-auth RCE and explicitly describes a standalone Python exploit with attack mechanics and a link to exploit details.

    03085698
    953 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Critical 9.3 RCE in OpenAM (CVE-2026-33439) allows unauthenticated attackers to execute OS commands via jato.clientSession. Patch your 16.0.5 servers now! #OpenAM #CyberSecurity #RCE #Deserialization #InfoSec #CVE202633439 #AccessManagement https://securityonline.info/openam-pre-auth-rce-vulnerability-cve-2026-33439/ https://t.co/KkpKKTevWN

    Post summary

    A critical RCE in OpenAM (CVE‑2026‑33439) is disclosed, and users are urged to patch to version 16.0.5 to mitigate unauthenticated OS command execution.

    01032416
    12.4K followersView on X
  • ET Labs@ET_Labs
    Disclosure

    29 new OPEN, 31 new PRO (29 + 2) Apache ActiveMQ (CVE-2026-40466), OpenAM (CVE-2026-33439), HumanitarianBait InfoStealer, Italiano Stealerano, Lumma Stealer, MagicG Stealer, TA569, LandUpdate808, ZPHP https://community.emergingthreats.net/t/ruleset-update-summary-2026-05-11-v11190/3313 https://t.co/yq1Mc1I183

    Post summary

    The post announces two new CVE identifiers for Apache ActiveMQ and OpenAM in a ruleset update, providing only product and CVE information without any exploits, patches, or evidence of active use.

    03020292
    5.7K followersView on X
  • Threat Intelligence@threatintel
    Disclosure

    #ThreatProtection #CVE-2026-33439 - OpenAM Pre-Auth RCE #vulnerability, read more about Symantec's protection: https://www.broadcom.com/support/security-center/protection-bulletin/cve-2026-33439-openam-pre-auth-rce-vulnerability

    Post summary

    The tweet announces CVE-2026-33439, a Pre-Auth Remote Code Execution vulnerability in OpenAM, and points to a Symantec protection bulletin for further details.

    010201.3K
    115.1K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-33439 - critical 🚨 OpenAM &lt;= 16.0.5 - Pre-Auth RCE via jato.clientSession Deserialization &gt; Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, Op... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-33439 @pdnuclei #NucleiTempl...

    Post summary

    The tweet announces a critical CVE-2026-33439 affecting OpenAM versions ≤16.0.5 with a pre‑authentication remote code execution flaw. No PoC, exploit, patch, or active exploitation details are provided.

    00012159
    930 followersView on X
  • cybrmonk@cybr_monk
    Exploit

    OpenAM Critical RCE (CVE-2026-33439) Exploit Code Now Public, Attackers Can Run Arbitrary Commands Without Auth https://cybrmonk.com/blog/openam-critical-rce-cve-2026-33439-exploit-code-now-public-attackers-can-run-arbitrary-commands-without-auth #cybersecurity #threatintelligence https://t.co/cErZIvIWUc

    Post summary

    The post announces that CVE-2026-33439 in OpenAM has a publicly available exploit enabling unauthenticated remote command execution, with an explicit PoC but no evidence of current attacks.

    0000188
    47 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    🚨 CVE-2026-33439 (ForgeRock OpenAM &lt;16.0.6, CVSS Critical): Pre-auth RCE via jato.clientSession Java deserialization. No creds needed → full OS exec. Multiple PoCs on GitHub since Apr 30. Your SSO/IAM gateway IS the breach point. Upgrade to 16.0.6 NOW. #ZeroDay #IAM

    Post summary

    The tweet announces the critical CVE‑2026‑33439 remote code execution flaw in ForgeRock OpenAM, highlights existing PoCs on GitHub, and urges an immediate patch to version 16.0.6.

    0001060
    210 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: A critical remote code execution #vulnerability in #OpenAM allows unauthenticated remote attackers to execute arbitrary commands on the host. #CVE-2026-33439 CVSS(4.0): 9.3. Read the advisory available at https://ccb.belgium.be/advisories/warning-remote-code-execution-vulnerability-openam-can-be-exploited-fully-compromise and #Patch #Patch #Patch

    Post summary

    The post alerts to a critical RCE in OpenAM, provides a CVE reference and CVSS score, and directs readers to an advisory that presumably contains a patch or mitigation.

    01000282
    7.2K followersView on X
  • Triune Digital Security Corporate LLP@triunedigisec
    Disclosure

    OpenAM affected by CVE-2026-33439, a pre-auth RCE vulnerability. #accessmanagement #vulnerability #remotecodeexecution https://t.co/QCaczbc5aI

    Post summary

    The tweet announces CVE-2026-33439 as a pre‑auth remote code execution flaw in OpenAM, providing technical details but no patch or exploit information.

    0000062
    106 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 OpenAM, Deserialization of Untrusted Data (CWE-502), #CVE-2026-33439 (CRITICAL) -DC-Jun2026-624 https://dailycve.com/openam-deserialization-of-untrusted-data-cwe-502-cve-2026-33439-critical-dc-jun2026-624/

    Post summary

    The tweet announces a newly disclosed critical CVE (CVE-2026-33439) affecting OpenAM deserialization of untrusted data, but it provides no further details on exploitation, patches, or technical aspects.

    0000052
    216 followersView on X
  • Hephaestvs@Vulcanux_
    Active Exploitation

    csirt_it: ‼ #OpenIdentityPlatform: rilevato sfruttamento della CVE-2026-33439, che interessa #OpenAM, piattaforma open‑source di Identity &amp; Access Management #IAM Rischio: 🔴 Tipologia: 🔸 Remote Code Execution 🔗 https://www.acn.gov.it/portale/w/openidentityplatform-rilevato-sfruttamento-della-cve-2026-33439 ⚠ Importan… https://t.co/PuCFUA6mvi

    Post summary

    The tweet alerts that CVE‑2026‑33439, a Remote Code Execution flaw in OpenAM, is being actively exploited, but does not provide any PoC, patch, or detailed technical data beyond the RCE classification.

    0000047
    609 followersView on X
  • Qubit@q810034
    Disclosure

    CVE-2026-33439 OpenAM pre-auth RCE , CVE-2021-35464 deserialization bypass for newer JDKs with command echo. https://t.co/ahqPtr2C69

    Post summary

    The tweet announces two CVEs—CVE‑2026‑33439 (OpenAM pre‑auth RCE) and CVE‑2021‑35464 (deserialization bypass affecting newer JDKs)—but provides no proof‑of‑concept, exploitation details, or patch information.

    00000108
    47 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `OpenIdentityPlatform OpenAM` is affected by a pre-authentication RCE vulnerability (CVE-2026-33439) due to `jato.clientSession` deserialization. Exploitation allows arbitrary code execution. #OpenAM #RCE #InfoSec https://www.pulsepatch.io/posts/cve-2026-33439-openam-pre-auth-rce-deserialization

    Post summary

    The post reports a pre-authentication remote code execution flaw in OpenIdentityPlatform OpenAM tied to jato.clientSession deserialization, enabling arbitrary code execution, and provides a link to an article with further details.

    0000077
    11 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33439 Remote Code Execution in OpenIdentityPlatform OpenAM Prior to 16.... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33439 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post announces CVE-2026-33439, a Remote Code Execution vulnerability in OpenIdentityPlatform OpenAM prior to version 16, but does not provide exploit details, active exploitation evidence, or mitigation guidance.

    0000092
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33439 Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Executi… https://www.cve.org/CVERecord?id=CVE-2026-33439

    Post summary

    The post announces a new CVE (2026-33439) in OpenAM, providing only a brief description of a pre‑authentication remote code execution flaw, without referencing PoCs, exploits, active attacks, or fixes.

    00000211
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33439: Pre-Authentication Remote Code E... OpenAM's jato.clientSession parameter bypasses CVE-2021-35464 whitelist fix—pre-auth RCE via Java deserialization on an... https://zerodaysignal.com/vulnerability/CVE-2026-33439 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-33439 is disclosed as a pre-authentication RCE vulnerability in OpenAM via Java deserialization, with a link to more details provided but no PoC, exploit tool, or active exploitation reports.

    00000101
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenidentityplatformopenam---

Explore more