SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-44793

HIGH · CVSS 7 EPSS 0.45% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

OpenAM prior to version 16.1.1 is vulnerable due to inconsistent encoding of user-supplied parameters in certain federation endpoints within non-default clustered configurations. This flaw allows unauthenticated attackers to craft requests that can execute scripts in the OpenAM origin, potentially leading to cross-site scripting (XSS) attacks. Organizations using OpenAM in clustered environments should prioritize applying the update to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-44793
Severity
HIGH
CVSS
7
EPSS
0.45%

Original NVD Description

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non-default clustered configuration inconsistently encode user-supplied parameters rendered into HTML in the SAML2 cluster cookie-hash redirect path. An unauthenticated attacker can induce a user to follow a crafted request and execute script in the OpenAM origin. This issue is fixed in version 16.1.1.