All verified exploits

CVE-2026-33439 Pre-Auth RCE via jato.clientSession Deserialization

Deterministic critical OpenAM Added cve-verified-cve-2026-33439

Detects OpenIdentityPlatform OpenAM instances before 16.0.6 vulnerable to pre-authentication remote code execution. The jato.clientSession HTTP parameter is deserialized using raw ObjectInputStream without class filtering — a bypass of the CVE-2021-35464 fix that only protected jato.pageSession. Any unauthenticated attacker can execute arbitrary commands.

Is your app exploitable through CVE-2026-33439?

Scan your domain free