CVE-2026-53660
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes the iPlanetDirectoryPro SSO cookie with HttpOnly disabled and without a protective SameSite default, and OAuth and OpenID Connect consent flows reuse that cookie through CsrfProtection as a CSRF token. When combined with same-origin cross-site scripting and a user following an attacker-controlled link, the cookie can be read and reused to steal the SSO session and complete attacker-driven consent grants. This issue is fixed in version 16.1.1.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.4
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.33%
- CWE
- CWE-1004, CWE-1188, CWE-1275
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- OpenIdentityPlatform OpenAM
Weakness type
Related vulnerabilities
- CVE-2026-22081 — Cookie without HTTPOnly Flag Vulnerability in Tenda Wireless Routers
- CVE-2025-53757 — Insecure Cookie Flags Vulnerability in Digisol DG-GR6821AC Router
- CVE-2025-0479 — Security Misconfiguration Vulnerability in CP Plus Router
- CVE-2021-42115 — Missing HTTPOnly flag on sensitive cookie in TopEase
- CVE-2026-25136 — Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
- CVE-2022-25172 — An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRo
- CVE-2022-21939 — Sensitive cookie without 'HttpOnly' flag in System Configuration Tool (SCT)
- CVE-2021-3706 — Sensitive Cookie Without 'HttpOnly' Flag in pi-hole/adminlte