Open Identity Platform's vulnerability exposure centers on its OpenAM identity and access management product, which serves as an authentication and authorization gateway in enterprise deployments. The recurring weakness classes—including unsafe deserialization, improper authentication logic, and miscellaneous implementation flaws—reflect the complexity of building a credential-handling and session-management platform; current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openidentityplatform over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33439CRITICAL Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via u | Apr 7, 2026 | 9.8 | 52 | NO | YES |
CVE-2023-37471CRITICAL Open Access Management (OpenAM) is an access management solution that includes Authentication, SSO, Authorization, Federation, Entitlements and Web Services Security. OpenAM up to | Jul 20, 2023 | 9.8 | 28 | NO | NO |
CVE-2022-34298MEDIUM The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack." | Jun 23, 2022 | 5.3 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openidentityplatform.
Media articles that mention a CVE ID that affects a product developed by Openidentityplatform — matched by CVE ID, not by vendor name.