CVE-2026-46619
## Summary **Description** An LDAP Injection (CWE-90) vulnerability in the MSISDN authentication module allows an unauthenticated, remote attacker to obtain an arbitrary OpenAM session without a password in the default trusted gateway configuration. This impacts OpenAM Community Edition through version 16.0.6. This issue was patched in version 16.1.1. ## Impact OpenAM deployments through version 16.0.6 that have MSISDN enabled are potentially affected. This enables a pre-authentication login bypass for any realm where an MSISDN module instance is enabled in an authentication chain and reachable through the trusted-gateway list, which allows all traffic by default. The request-supplied MSISDN value was concatenated directly into an LDAP search filter. The resulting OpenAM session is a normal authenticated session for the matched user. ## Patch This has been patched in OpenAM Community Edition version 16.1.1. Users are encouraged to update to the latest release.
Properties
- ghsa_id
- GHSA-xq73-fvmr-jvmm
- summary
- OpenAM Authentication Bypass via MSISDN LDAP Injection
- severity
- high
- cve_id
- CVE-2026-46619
- is_ghsa_only
- false
- ghsa_published
- 2026-06-26T17:32:18Z
- source_url
- https://github.com/advisories/GHSA-xq73-fvmr-jvmm
- ghsa_updated
- 2026-06-26T17:32:19Z
Related Entities (5)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (2)
Explore deeper with Ninja Signal's threat intelligence graph