highVulnerability

CVE-2026-46619

## Summary **Description** An LDAP Injection (CWE-90) vulnerability in the MSISDN authentication module allows an unauthenticated, remote attacker to obtain an arbitrary OpenAM session without a password in the default trusted gateway configuration. This impacts OpenAM Community Edition through version 16.0.6. This issue was patched in version 16.1.1. ## Impact OpenAM deployments through version 16.0.6 that have MSISDN enabled are potentially affected. This enables a pre-authentication login bypass for any realm where an MSISDN module instance is enabled in an authentication chain and reachable through the trusted-gateway list, which allows all traffic by default. The request-supplied MSISDN value was concatenated directly into an LDAP search filter. The resulting OpenAM session is a normal authenticated session for the matched user. ## Patch This has been patched in OpenAM Community Edition version 16.1.1. Users are encouraged to update to the latest release.

Properties

ghsa_id
GHSA-xq73-fvmr-jvmm
summary
OpenAM Authentication Bypass via MSISDN LDAP Injection
severity
high
cve_id
CVE-2026-46619
is_ghsa_only
false
ghsa_published
2026-06-26T17:32:18Z
source_url
https://github.com/advisories/GHSA-xq73-fvmr-jvmm
ghsa_updated
2026-06-26T17:32:19Z

Related Entities (5)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]maven/org.openidentityplatform.openam:openam-auth-msisdn

AFFECTS (1)

[Software]maven/org.openidentityplatform.openam:openam-auth-msisdn

HAS_WEAKNESS (2)

[Weakness]Initialization of a Resource with an Insecure Default
[Weakness]Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-46619 — Ninja Signal Threat Intelligence | Ninja Signal