highVulnerability

CVE-2026-47424

## Summary **Description** A Protection Mechanism Failure (CWE-693) in OpenAM's server-side scripting sandbox allows an authenticated script author execute operating-system commands from the OpenAM JVM with the default class allow and deny lists. This impacts OpenAM Community Edition through version 16.0.6. This issue was patched in version 16.1.1. ## Impact An authenticated user (for example, a realm admin) who can create or edit server-side scripts for an executed context can run OS commands as the OpenAM application server admin. For a sub-realm `RealmAdmin`, this crosses the documented boundary from realm-scoped administration to JVM/host execution, effectively compromising the whole OpenAM process and every realm it serves. The sandbox is the only code-level defense between a realm script author and arbitrary JVM/OS execution. ## Patch This has been patched in OpenAM Community Edition version 16.1.1. Users are encouraged to update to the latest release.

Properties

ghsa_id
GHSA-69j4-qvqr-hpw3
severity
high
summary
OpenAM Authenticated RCE via Groovy Sandbox Escape
cve_id
CVE-2026-47424
is_ghsa_only
false
ghsa_published
2026-06-29T17:43:29Z
source_url
https://github.com/advisories/GHSA-69j4-qvqr-hpw3
ghsa_updated
2026-06-29T17:43:30Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]maven/org.openidentityplatform.openam:openam-scripting

AFFECTS (1)

[Software]maven/org.openidentityplatform.openam:openam-scripting

HAS_WEAKNESS (1)

[Weakness]Protection Mechanism Failure

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-47424 — Ninja Signal Threat Intelligence | Ninja Signal