CVE-2026-62379

CRITICALExploit Available
Source

CVE-2026-62379: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCa...

NVD/NISTPublished Sep 15, 2026Modified 12h agoNVDMaturity: weaponized

CVSS Scores

9.8
Base Score
Exploitability3.9
Impact5.9

EPSS Score

EPSS Probability1.09%

Higher than 64% of all CVEs

Active exploitation confirmed

EPSS prediction is low but real-world exploitation has been observed. Prioritize remediation regardless of EPSS score.

Exploit intelligence for CVE-2026-62379

Kaitan ID has tracked 2 public exploits for this vulnerability across exploitdb (1), nvd_ref (1).

  • nvd_refReference: Github
  • exploitdbExploit-DB Search: CVE-2026-62379
View all exploit details

Exploit maturity

WeaponizedActive exploit code is publicly available. This vulnerability has been weaponized and may be actively targeted.

  • Public exploit code is available.
  • No vendor patch available yet.

Exploitation probability (EPSS)

EPSS exploitation probability: 1.1%. This vulnerability ranks in the top 36% of all CVEs by exploitation likelihood. Last updated on Sep 15, 2026.

Attack surface

This vulnerability is exploitable over the network. low complexity. no privileges required. no user interaction needed. impact is limited to the vulnerable component.

Primary source

Original advisory or reference for this vulnerability (via NVD).

https://github.com/OpenIdentityPlatform/OpenAM/commit/edcf968cad91a78b932dba4ad559ef94cbf35f5a