CVE-2026-48717

CVE-2026-48717 is a medium-severity security vulnerability in org.openidentityplatform.openam:openam-oauth2 (maven), affecting versions <= 16.0.6. It is fixed in 16.1.1.

Does this CVE actually affect you?

Kodem shows which CVEs are reachable and running in your applications, so you fix what's exploitable, not just what's listed.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Runtime intelligence, not another scanner.

Summary

OpenAM OAuth Authorization Bypass via PKCE Challenge

Description

An Improper Authorization (CWE-285) issue in OpenAM's OAuth2 authorization-code grant allows a PKCE-protected authorization code to be redeemed without the required code_verifier. This affects OpenAM Community Edition through version 16.0.6 and was patched in version 16.1.1.

The authorize endpoint stores a code_challenge on the issued code, but the token endpoint only requires a code_verifier when the realm-wide codeVerifierEnforced setting is enabled, which ships disabled by default. With that setting off, the stored challenge is checked only if the caller supplies a verifier, so omitting the parameter skips PKCE verification entirely.

Impact

OpenAM Community Edition deployments through version 16.0.6 using the default OAuth2 provider configuration are potentially affected. For public clients, an attacker who intercepts an authorization code can exchange it for tokens without knowing the verifier. For confidential clients, the attacker additionally needs client authentication material or an execution context that can redeem the code. A token request supplying an incorrect verifier is still rejected. The bypass is specifically the missing-parameter path.

Affected versions

org.openidentityplatform.openam:openam-oauth2 (<= 16.0.6)

Security releases

org.openidentityplatform.openam:openam-oauth2 → 16.1.1 (maven)

Kodem intelligence

Severity tells you how bad this could be in the worst case. It does not tell you whether you are exposed. Exploitability and impact are functions of runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A vulnerable package can sit in your dependency tree and never run.

Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter. Kodem's runtime-powered SCA identifies whether this CVE is reachable in your applications.

Already deployed Kodem?

See it in your environmentNew to Kodem? Get a demo →

Remediation advice

This has been patched in OpenAM Community Edition version 16.1.1. Users are encouraged to update to the latest release.

Frequently Asked Questions

  1. What is CVE-2026-48717? CVE-2026-48717 is a medium-severity security vulnerability in org.openidentityplatform.openam:openam-oauth2 (maven), affecting versions <= 16.0.6. It is fixed in 16.1.1.
  2. Which versions of org.openidentityplatform.openam:openam-oauth2 are affected by CVE-2026-48717? org.openidentityplatform.openam:openam-oauth2 (maven) versions <= 16.0.6 is affected.
  3. Is there a fix for CVE-2026-48717? Yes. CVE-2026-48717 is fixed in 16.1.1. Upgrade to this version or later.
  4. Is CVE-2026-48717 exploitable, and should I be worried? Whether CVE-2026-48717 is exploitable in your environment depends on whether the vulnerable code is present and reachable. A CVSS score is a worst-case rating; it does not account for your specific deployment, configuration, or usage patterns. Kodem, an Intelligent Application Security platform, uses runtime intelligence to show which vulnerabilities actually execute in production, so you can focus on the ones that represent real risk. Get a demo
  5. What actually determines whether CVE-2026-48717 is exploitable, and how bad it is? Exploitability and impact are not fixed properties of a CVE. They depend on runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A high CVSS score on a dependency that never runs is not the same as real risk. Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter.
  6. How do I fix CVE-2026-48717? Upgrade org.openidentityplatform.openam:openam-oauth2 to 16.1.1 or later.

Other vulnerabilities in org.openidentityplatform.openam:openam-oauth2

Stop the waste.
Protect your environment with Kodem.