Researchers disclosed critical pre-authentication remote code execution flaws in ForgeRock/OpenAM that let attackers execute code without logging in by abusing unsafe Java deserialization in request parameters. PortSwigger reported CVE-2021-35464 in ForgeRock OpenAM, while later research detailed CVE-2026-33439 in OpenIdentityPlatform OpenAM, where attacker-controlled data in the jato.clientSession parameter could reach ApplicationObjectInputStream.readObject() without class filtering.
The newer flaw affected unauthenticated password-reset endpoints including /openam/ui/PWResetUserValidation and /openam/ui/PWResetQuestion, where JSP processing of <jato:form> tags exposed the vulnerable code path. Researchers said a crafted gadget chain could achieve code execution with a single GET request on OpenAM 16.0.5, and that version 16.0.6 fixed the issue by routing Encoder.deserialize() through the same whitelist-based deserialization protections previously applied to jato.pageSession; the bug was assigned CVSS 9.8 and mapped to CWE-502.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The disclosure states that OpenAM 16.0.6 fixes CVE-2026-33439 by routing Encoder.deserialize() through the same whitelist-based deserialization logic already used for jato.pageSession.
Hacktron disclosed CVE-2026-33439, a critical pre-authentication RCE in OpenIdentityPlatform OpenAM caused by unsafe deserialization of the jato.clientSession parameter on unauthenticated password reset pages. The write-up states the issue was tested on OpenAM 16.0.5 and can be exploited with a single GET request.
PortSwigger Research published details of a pre-authentication remote code execution vulnerability in ForgeRock OpenAM tracked as CVE-2021-35464.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.