<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:36:48 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-368588</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-368588</link>
      <description>EUVD-2026-368588</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-368588</guid>
    </item>
    <item>
      <title>fkie_cve-2026-62379</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-62379</link>
      <description>&lt;p&gt;Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUtils to load and instantiate without verifying that it implements DSAMECallbackInterface. Default configurations expose the endpoint without authentication, allowing attacker-controlled class initialization and unsafe deserialization of a serialized Subject value to execute code in the server process. Enabling sunRemoteAuthSecurityEnabled does not prevent the vulnerable parsing and instantiation because its check occurs later. This issue is fixed in version 16.1.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUtils to load and instantiate without verifying that it implements DSAMECallbackInterface. Default configurations expose the endpoint without authentication, allowing attacker-controlled class initialization and unsafe deserialization of a serialized Subject value to execute code in the server process. Enabling sunRemoteAuthSecurityEnabled does not prevent the vulnerable parsing and instantiation because its check occurs later. This issue is fixed in version 16.1.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-62379</guid>
    </item>
    <item>
      <title>GHSA-wg5r-wc3x-39vc — OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wg5r-wc3x-39vc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.openidentityplatform.openam:openam-core&lt;/p&gt;
&lt;p&gt;## Summary
A pre-authentication remote code execution vulnerability affects OpenAM. The
remote authentication endpoint (`/authservice`, PLL) accepts an XML element
that names an arbitrary Java class, which the server then loads and
instantiates without validation. On a default configuration this is reachable
**without authentication** and allows an attacker to run code on the server.&lt;/p&gt;
&lt;p&gt;## Impact
Unauthenticated remote code execution / full server compromise on any OpenAM
instance with default settings.&lt;/p&gt;
&lt;p&gt;## Affected
All releases up to and including 16.1.1 (the defect predates the Open Identity
Platform fork).&lt;/p&gt;
&lt;p&gt;## Remediation
Upgrade to `16.1.2`. The fix resolves the class named in a `&amp;lt;CustomCallback&amp;gt;`
element without running its static initialisers and rejects it unless it
implements `DSAMECallbackInterface`, and it constrains deserialisation of the
serialised `Subject` value to a class allowlist.&lt;/p&gt;
&lt;p&gt;## Interim mitigation
If you cannot upgrade immediately:&lt;/p&gt;
&lt;p&gt;- **Restrict or block external network access to `/authservice`.** This is the
  only reliable mitigation.
- Optionally, **block PLL requests carrying a `&amp;lt;CustomCallback className=&amp;#34;...&amp;#34;&amp;gt;`
  element** at the reverse proxy or WAF. That element is only produced for custom
  `DSAMECallbackInterface` callbacks, so most deployments never send it — confirm
  against your own traffic before enforcing.
- **Enabling `sunRemoteAuthSecurityEnabled` does *not* mitigate this issue.** The
  remote-auth security token is checked in `AuthXMLH…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.openidentityplatform.openam:openam-core&lt;/p&gt;
&lt;p&gt;## Summary
A pre-authentication remote code execution vulnerability affects OpenAM. The
remote authentication endpoint (`/authservice`, PLL) accepts an XML element
that names an arbitrary Java class, which the server then loads and
instantiates without validation. On a default configuration this is reachable
**without authentication** and allows an attacker to run code on the server.&lt;/p&gt;
&lt;p&gt;## Impact
Unauthenticated remote code execution / full server compromise on any OpenAM
instance with default settings.&lt;/p&gt;
&lt;p&gt;## Affected
All releases up to and including 16.1.1 (the defect predates the Open Identity
Platform fork).&lt;/p&gt;
&lt;p&gt;## Remediation
Upgrade to `16.1.2`. The fix resolves the class named in a `&amp;lt;CustomCallback&amp;gt;`
element without running its static initialisers and rejects it unless it
implements `DSAMECallbackInterface`, and it constrains deserialisation of the
serialised `Subject` value to a class allowlist.&lt;/p&gt;
&lt;p&gt;## Interim mitigation
If you cannot upgrade immediately:&lt;/p&gt;
&lt;p&gt;- **Restrict or block external network access to `/authservice`.** This is the
  only reliable mitigation.
- Optionally, **block PLL requests carrying a `&amp;lt;CustomCallback className=&amp;#34;...&amp;#34;&amp;gt;`
  element** at the reverse proxy or WAF. That element is only produced for custom
  `DSAMECallbackInterface` callbacks, so most deployments never send it — confirm
  against your own traffic before enforcing.
- **Enabling `sunRemoteAuthSecurityEnabled` does *not* mitigate this issue.** The
  remote-auth security token is checked in `AuthXMLH…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wg5r-wc3x-39vc</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-62379</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-62379</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: openam&lt;/p&gt;
&lt;p&gt;Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUtils to load and instantiate without verifying that it implements DSAMECallbackInterface. Default configurations expose the endpoint without authentication, allowing attacker-controlled class initialization and unsafe deserialization of a serialized Subject value to execute code in the server process. Enabling sunRemoteAuthSecurityEnabled does not prevent the vulnerable parsing and instantiation because its check occurs later. This issue is fixed in version 16.1.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: openam&lt;/p&gt;
&lt;p&gt;Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUtils to load and instantiate without verifying that it implements DSAMECallbackInterface. Default configurations expose the endpoint without authentication, allowing attacker-controlled class initialization and unsafe deserialization of a serialized Subject value to execute code in the server process. Enabling sunRemoteAuthSecurityEnabled does not prevent the vulnerable parsing and instantiation because its check occurs later. This issue is fixed in version 16.1.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-62379</guid>
    </item>
  </channel>
</rss>
