CVE-2026-62379
CRITICALExploit AvailableCVE-2026-62379: Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCa...
CVSS Scores
EPSS Score
Higher than 64% of all CVEs
Active exploitation confirmed
EPSS prediction is low but real-world exploitation has been observed. Prioritize remediation regardless of EPSS score.
Exploit intelligence for CVE-2026-62379
Kaitan ID has tracked 2 public exploits for this vulnerability across exploitdb (1), nvd_ref (1).
- nvd_refReference: Github
- exploitdbExploit-DB Search: CVE-2026-62379
Exploit maturity
Weaponized — Active exploit code is publicly available. This vulnerability has been weaponized and may be actively targeted.
- Public exploit code is available.
- No vendor patch available yet.
Exploitation probability (EPSS)
EPSS exploitation probability: 1.1%. This vulnerability ranks in the top 36% of all CVEs by exploitation likelihood. Last updated on Sep 15, 2026.
Attack surface
This vulnerability is exploitable over the network. low complexity. no privileges required. no user interaction needed. impact is limited to the vulnerable component.
Primary source
Original advisory or reference for this vulnerability (via NVD).
https://github.com/OpenIdentityPlatform/OpenAM/commit/edcf968cad91a78b932dba4ad559ef94cbf35f5a