Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-69j4-qvqr-hpw3 | OpenAM Authenticated RCE via Groovy Sandbox Escape |
Tue, 15 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openidentityplatform
Openidentityplatform openam |
|
| Vendors & Products |
Openidentityplatform
Openidentityplatform openam |
Tue, 15 Sep 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated server-side script author to escape the scripting sandbox despite the default class allow and deny lists. A user such as a sub-realm RealmAdmin who can create or edit a script in an executed context can invoke operating-system commands as the OpenAM application server account, crossing the realm-scoped administration boundary and compromising the JVM and every realm it serves. This issue is fixed in version 16.1.1. | |
| Title | OpenAM Authenticated RCE via Groovy Sandbox Escape | |
| Weaknesses | CWE-693 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T12:47:22.878Z
Reserved: 2026-05-19T19:37:43.526Z
Link: CVE-2026-47424
Updated: 2026-09-15T12:46:59.977Z
Status : Received
Published: 2026-09-15T10:17:05.077
Modified: 2026-09-15T13:16:41.853
Link: CVE-2026-47424
No data.
OpenCVE Enrichment
Updated: 2026-09-15T11:45:17Z
-
CWE-693
Protection Mechanism Failure
Github GHSA