S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Apr 17, 2026

CVE-2026-33439 Scanner

CVE-2026-33439 Scanner - Remote Code Execution (RCE) vulnerability in OpenAM

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.3k
Times Used
continuous scan runs
6k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-33439
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP parameter. This bypasses the WhitelistObjectInputStream mitigation that was applied to the jato.pageSession parameter after CVE-2021-35464. An unauthenticated attacker can achieve arbitrary command execution on the server by sending a crafted serialized Java object as the jato.clientSession GET/POST parameter to any JATO ViewBean endpoint whose JSP contains <jato:form> tags (e.g., the Password Reset pages). This vulnerability is fixed in 16.0.6.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
OpenAMby OpenIdentityPlatform
< 16.0.6
Updated Sep 9, 2026View on NVD →
Detail

OpenAM is a widely used access management solution that provides authentication, authorization, and identity services in enterprise environments. Developed by OpenIdentityPlatform, its primary users include large organizations that require centralized access control mechanisms. OpenAM is often integrated into complex network infrastructures to provide comprehensive access security. It supports web and application servers across various platforms, making it a versatile option for cloud and on-prem solutions. As an open-source project, it attracts developers and businesses that benefit from its extensibility and community support.

This scanner detects a significant Remote Code Execution (RCE) vulnerability in OpenAM versions <= 16.0.5. This vulnerability stems from insecure deserialization of Java objects through the jato.clientSession parameter. An attacker can execute arbitrary commands on the server by submitting a crafted serialized object. The system is vulnerable even before authentication, offering attackers a pathway to exploit without prior access to credentials.

The vulnerability resides in the JATO framework endpoints, particularly when JSP pages with tags are involved. The scanner targets the 'jato.clientSession' parameter to identify if backend logic performs unsafe Java deserialization. Through a crafted client-side request, the vulnerability allows direct interaction with the affected endpoint, simulating conditions to trigger a response, indicating the presence of the flaw.

If malicious actors exploit this RCE vulnerability, they could gain unauthorized control over the affected server, executing commands seamlessly. This poses risks of data theft, system compromise, and lateral movement within the network. Organizations may face severe security breaches leading to downtime, financial loss, and reputational damage.

REFERENCES

Solution Advice
  • Upgrade to OpenAM 16.0.6 or later to mitigate the vulnerability.
  • Employ application security controls to monitor and limit suspicious activities.
  • Apply additional network segmentation to isolate critical systems from vulnerable components.
  • Regularly review and update system configurations in accordance with security best practices.
  • Enhance IT staff's capability with focused training on identifying deserialization attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.