CVE-2026-47424
## Summary **Description** A Protection Mechanism Failure (CWE-693) in OpenAM's server-side scripting sandbox allows an authenticated script author execute operating-system commands from the OpenAM JVM with the default class allow and deny lists. This impacts OpenAM Community Edition through version 16.0.6. This issue was patched in version 16.1.1. ## Impact An authenticated user (for example, a realm admin) who can create or edit server-side scripts for an executed context can run OS commands as the OpenAM application server admin. For a sub-realm `RealmAdmin`, this crosses the documented boundary from realm-scoped administration to JVM/host execution, effectively compromising the whole OpenAM process and every realm it serves. The sandbox is the only code-level defense between a realm script author and arbitrary JVM/OS execution. ## Patch This has been patched in OpenAM Community Edition version 16.1.1. Users are encouraged to update to the latest release.
Properties
- ghsa_id
- GHSA-69j4-qvqr-hpw3
- severity
- high
- summary
- OpenAM Authenticated RCE via Groovy Sandbox Escape
- cve_id
- CVE-2026-47424
- is_ghsa_only
- false
- ghsa_published
- 2026-06-29T17:43:29Z
- source_url
- https://github.com/advisories/GHSA-69j4-qvqr-hpw3
- ghsa_updated
- 2026-06-29T17:43:30Z
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph