{"id":"CVE-2026-47424","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-47424","summary":"OpenAM Authenticated RCE via Groovy Sandbox Escape","details":"## Summary\n\n**Description**\n\nA Protection Mechanism Failure (CWE-693) in OpenAM's server-side scripting sandbox allows an authenticated script author execute operating-system commands from the OpenAM JVM with the default class allow and deny lists. This impacts OpenAM Community Edition through version 16.0.6. This issue was patched in version 16.1.1.\n\n## Impact\nAn authenticated user (for example, a realm admin) who can create or edit server-side scripts for an executed context can run OS commands as the OpenAM application server admin. For a sub-realm `RealmAdmin`, this crosses the documented boundary from realm-scoped administration to JVM/host execution, effectively compromising the whole OpenAM process and every realm it serves. The sandbox is the only code-level defense between a realm script author and arbitrary JVM/OS execution.\n\n## Patch\nThis has been patched in OpenAM Community Edition version 16.1.1. Users are encouraged to update to the latest release.","published":"2026-06-29T17:43:29Z","modified":"2026-06-29T18:00:07.862264866Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Maven","name":"org.openidentityplatform.openam:openam-scripting","fixedVersion":"16.1.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-69j4-qvqr-hpw3"},{"type":"PACKAGE","url":"https://github.com/OpenIdentityPlatform/OpenAM"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-06-29T18:00:07.862264866Z"}}