<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:56:56.967392+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-368588</id>
    <title>EUVD-2026-368588</title>
    <updated>2026-10-03T04:56:57.055989+00:00</updated>
    <content>EUVD-2026-368588</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-368588"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-62379</id>
    <title>fkie_cve-2026-62379</title>
    <updated>2026-10-03T04:56:57.056038+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUtils to load and instantiate without verifying that it implements DSAMECallbackInterface. Default configurations expose the endpoint without authentication, allowing attacker-controlled class initialization and unsafe deserialization of a serialized Subject value to execute code in the server process. Enabling sunRemoteAuthSecurityEnabled does not prevent the vulnerable parsing and instantiation because its check occurs later. This issue is fixed in version 16.1.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-62379"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wg5r-wc3x-39vc</id>
    <title>GHSA-wg5r-wc3x-39vc — OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback</title>
    <updated>2026-10-03T04:56:57.056092+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.openidentityplatform.openam:openam-core</p>
<p>## Summary
A pre-authentication remote code execution vulnerability affects OpenAM. The
remote authentication endpoint (`/authservice`, PLL) accepts an XML element
that names an arbitrary Java class, which the server then loads and
instantiates without validation. On a default configuration this is reachable
**without authentication** and allows an attacker to run code on the server.</p>
<p>## Impact
Unauthenticated remote code execution / full server compromise on any OpenAM
instance with default settings.</p>
<p>## Affected
All releases up to and including 16.1.1 (the defect predates the Open Identity
Platform fork).</p>
<p>## Remediation
Upgrade to `16.1.2`. The fix resolves the class named in a `&lt;CustomCallback&gt;`
element without running its static initialisers and rejects it unless it
implements `DSAMECallbackInterface`, and it constrains deserialisation of the
serialised `Subject` value to a class allowlist.</p>
<p>## Interim mitigation
If you cannot upgrade immediately:</p>
<p>- **Restrict or block external network access to `/authservice`.** This is the
  only reliable mitigation.
- Optionally, **block PLL requests carrying a `&lt;CustomCallback className="..."&gt;`
  element** at the reverse proxy or WAF. That element is only produced for custom
  `DSAMECallbackInterface` callbacks, so most deployments never send it — confirm
  against your own traffic before enforcing.
- **Enabling `sunRemoteAuthSecurityEnabled` does *not* mitigate this issue.** The
  remote-auth security token is checked in `AuthXMLH…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wg5r-wc3x-39vc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-62379</id>
    <title>UBUNTU-CVE-2026-62379</title>
    <updated>2026-10-03T04:56:57.056176+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: openam</p>
<p>Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUtils to load and instantiate without verifying that it implements DSAMECallbackInterface. Default configurations expose the endpoint without authentication, allowing attacker-controlled class initialization and unsafe deserialization of a serialized Subject value to execute code in the server process. Enabling sunRemoteAuthSecurityEnabled does not prevent the vulnerable parsing and instantiation because its check occurs later. This issue is fixed in version 16.1.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-62379"/>
  </entry>
</feed>
