OpenAM ships a legacy JAX-RPC SOAP interface, deployed by default and reachable at /jaxrpc/* , through which the legacy remote SDK clients used by some deployments (older remote policy agents, ssoadm , the remote configuration SDK) talk to the server's configuration store. One operation of that interface takes a Java class name from the request and loads and instantiates it before checking that it is of the expected type — and the operation performs no real authentication of its own: the session identifier it accepts is never actually verified.
This advisory is published ahead of the fixed release so that operators can apply the workarounds below. Technical details are deliberately withheld until OpenAM 16.1.3 is available.
An unauthenticated remote attacker who can reach the JAX-RPC interface can make OpenAM load and instantiate any class available on the server's classpath, with the privileges of the OpenAM process. Reliably, this can crash or degrade the server (denial of service) and lets the attacker probe which classes are present on the classpath. Because OpenAM's classpath includes general-purpose libraries with known reflection/deserialization gadget chains — the same class of primitive behind the previously published CVE-2026-62379 — the theoretical ceiling is remote code execution; this has not been independently demonstrated against a specific gadget.
All OpenAM releases up to and including 16.1.2.
Fixed in OpenAM 16.1.3. Note the fix requires every caller of this operation — including the legacy remote SDK and ssoadm — to present a session that OpenAM actually validates; a request that previously worked with no session, or with a session OpenAM never checked, is now refused.
Until 16.1.3 is deployed:
Restrict network access to /jaxrpc/* at the reverse proxy or firewall to only the hosts that run legacy remote SDK clients or agents against this server; block it entirely if nothing in the deployment uses the legacy remote SDK.
Where the interface must stay reachable , monitor for SOAP requests to it from unexpected sources.
This interface should never be exposed to the public internet, as with any OpenAM administrative interface.
Reported independently by @manus-use and @alex-sc .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
