{"id":"CVE-2026-44202","aliases":["GHSA-c556-q2mh-477v"],"url":"https://o3.security/vulnerability/CVE-2026-44202","summary":"OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice`","details":"Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbitrary notification URL without requiring an administrative or application client token. SessionRequestHandler passes the attacker-controlled destination to the session listener service, causing the OpenAM server to make outbound requests and potentially disclose session-related notification data to an attacker-controlled destination. This issue is fixed in version 16.1.1.","published":"2026-09-15T09:47:00.562Z","modified":"2026-09-17T08:08:37.620785Z","cvss":null,"epss":{"score":0.00317,"percentile":0.24626,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.openidentityplatform.openam:openam-core","fixedVersion":"16.1.1"}],"fix":{"url":"https://github.com/OpenIdentityPlatform/OpenAM/commit/a13a4b63ae0e0670c63cbcfa79586407408b3920","label":"OpenIdentityPlatform/OpenAM@a13a4b6"},"references":[{"type":"WEB","url":"https://github.com/OpenIdentityPlatform/OpenAM/releases/tag/16.1.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44202.json"},{"type":"ADVISORY","url":"https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-c556-q2mh-477v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44202"},{"type":"FIX","url":"https://github.com/OpenIdentityPlatform/OpenAM/commit/a13a4b63ae0e0670c63cbcfa79586407408b3920"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-17T08:08:37.620785Z"}}