Search/CVE-2026-41573
CVE

CVE-2026-41573

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() passes the _queryId parameter from /json/{realm}/users to CrestQuery with escapeQueryId disabled, bypassing protection added for CVE-2021-29156. The unescaped value reaches DJLDAPv3Repo.getFilter(), where it is concatenated into an LDAP filter, allowing an authenticated attacker to inject LDAP metacharacters for user enumeration and blind LDAP injection. This issue is fixed in version 16.1.1.

CVSS v3.1
EPSS
0.36%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Sep 16, 2026Sep 17, 2026
0.13pp
0.50% → 0.36% over 2 tracked changes
Connections
1 relationships
Timeline
disclosure → media coverage
Sep 15, 2026
Disclosure — published as a CVE record.