Openidentityplatform
19 CVEs tracked since 2026. Since Sep 2026, none of them reached CISA KEV.
Openidentityplatform CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-09 | 19 | 0 |
Products
The products that kept showing up in Openidentityplatform's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Openidentityplatform.
- CVE-2026-46495OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI—
- CVE-2026-48717OpenAM OAuth Authorization Bypass via PKCE Challenge—
- CVE-2026-47426OpenAM OAuth Client Impersonation via JWKS Resolver Cache—
- CVE-2026-47424OpenAM Authenticated RCE via Groovy Sandbox Escape—
- CVE-2026-41573OpenAM LDAP Injection via `_queryId` Parameter—
- CVE-2026-62280OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page6.1
- CVE-2026-45051OpenAM Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage—
- CVE-2026-62263OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass—
- CVE-2026-46623OpenAM Account Takeover via Unverified Password Change in OAuth2 Module—
- CVE-2026-46619OpenAM Authentication Bypass via MSISDN LDAP Injection—
- CVE-2026-46498OpenAM Arbitrary OAuth Token Minting via Push Registration—
- CVE-2026-45794OpenAM Unsafe Java Deserialization via SNS—
- CVE-2026-45048OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC8.5
- CVE-2026-44203OpenAM: Pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)—
- CVE-2026-44202OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice`—
The record
- Peak rank
- #58 in Sep 2026
- Busiest month shown
- Sep 2026, 19 CVEs
- Months with a KEV entry
- 0 since Sep 2026
- Monthly snapshots
- 1 since 2026