{"id":"CVE-2026-47424","aliases":["GHSA-69j4-qvqr-hpw3"],"url":"https://o3.security/vulnerability/CVE-2026-47424","summary":"OpenAM Authenticated RCE via Groovy Sandbox Escape","details":"## Summary\n\n**Description**\n\nA Protection Mechanism Failure (CWE-693) in OpenAM's server-side scripting sandbox allows an authenticated script author execute operating-system commands from the OpenAM JVM with the default class allow and deny lists. This impacts OpenAM Community Edition through version 16.0.6. This issue was patched in version 16.1.1.\n\n## Impact\nAn authenticated user (for example, a realm admin) who can create or edit server-side scripts for an executed context can run OS commands as the OpenAM application server admin. For a sub-realm `RealmAdmin`, this crosses the documented boundary from realm-scoped administration to JVM/host execution, effectively compromising the whole OpenAM process and every realm it serves. The sandbox is the only code-level defense between a realm script author and arbitrary JVM/OS execution.\n\n## Patch\nThis has been patched in OpenAM Community Edition version 16.1.1. Users are encouraged to update to the latest release.","published":"2026-09-15T09:56:24.707Z","modified":"2026-09-25T08:21:33.328124Z","cvss":null,"epss":{"score":0.00354,"percentile":0.28993,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.openidentityplatform.openam:openam-scripting","fixedVersion":"16.1.1"}],"fix":{"url":"https://github.com/OpenIdentityPlatform/OpenAM/commit/5c843cc7d5d89d908a2222bf3693754f94811599","label":"OpenIdentityPlatform/OpenAM@5c843cc"},"references":[{"type":"WEB","url":"https://github.com/OpenIdentityPlatform/OpenAM/releases/tag/16.1.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47424.json"},{"type":"ADVISORY","url":"https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-69j4-qvqr-hpw3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47424"},{"type":"FIX","url":"https://github.com/OpenIdentityPlatform/OpenAM/commit/5c843cc7d5d89d908a2222bf3693754f94811599"},{"type":"PACKAGE","url":"https://github.com/OpenIdentityPlatform/OpenAM"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-25T08:21:33.328124Z"}}