CVE-2026-33439 is an unsafe Java deserialization vulnerability in OpenIdentityPlatform OpenAM before version 16.0.6. Attacker-controlled data supplied through the jato.clientSession HTTP parameter is decoded and deserialized through an unfiltered ObjectInputStream path. This path was not covered by the whitelist-based deserialization protection previously introduced for the separate jato.pageSession parameter following CVE-2021-35464. The vulnerable processing occurs when JATO ViewBean pages containing JATO form tags initialize client-session attributes. Crafted serialized objects can invoke available gadget chains and execute attacker-controlled code in the OpenAM server process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
The repository is a standalone command-execution exploit implementation claiming to target CVE-2026-33439 in OpenAM. It contains four files: README.md documents the mechanism and usage; exploit.py builds and delivers the payload; setup.sh downloads dependencies and compiles the builder; and src/PayloadBuilder.java constructs the gadget and generates its Java translet from readable source. There is no exploit-framework integration or opaque embedded serialized blob. PayloadBuilder compiles EvilTranslet to Java 8 bytecode, places it in external Apache Xalan TemplatesImpl, and uses an Apache Click ColumnComparator configured for outputProperties inside a PriorityQueue. It populates queue internals reflectively rather than adding elements through the armed comparator, avoiding premature local gadget activation. It checks the class-file magic/version and Java serialization magic before emitting unpadded Base64URL. An optional compatibility mode prepends a zero byte before encoding. The Python driver sends the payload in the jato.clientSession GET parameter and places the selected command in the cmd header. The translet accesses JATO's current request and response, runs /bin/sh -c, merges stdout/stderr, and attempts to write the output back to the response. The driver supports an alternate endpoint, explicit proxy, timeout, and payload-only output. TLS certificate validation is disabled by default and enabled with --verify-tls. It prints HTTP status and response data even for HTTP error responses, but does not independently verify exploitation success. Its distinctive User-Agent is OpenAM-cleanroom-CVE-2026-33439/1.0. Static inspection shows a coherent exploit attempt rather than a detection-only script, and no obvious fake-exploit behavior or unrelated malicious callbacks. However, execution was not tested, the claimed CVE association and affected OpenAM versions are not independently established by the supplied files, and compatibility depends on the target's deserialization behavior, available classes, JVM restrictions, and response state. Dependency versions describe the local build inputs, not confirmed vulnerable OpenAM releases. The setup script prints SHA-256 hashes but does not compare them against trusted expected values, and it reuses existing JARs without validation. Repository URL, git reference, archive path, and archive size were not supplied; empty metadata and a zero archive-size placeholder reflect that absence. Listed file sizes total 15,465 bytes.
This two-file repository contains a standalone Python 3 exploit and a short usage README for CVE-2026-33439. CVE-2026-33439.py embeds a serialized Java gadget chain based on PriorityQueue, OpenAM Apache Click Column comparator behavior, and Xalan TemplatesImpl. It patches an EvilTranslet command slot at runtime, URL-safe-Base64 encodes the serialized object, then submits it as the jato.clientSession parameter. The tool automatically probes three OpenAM UI/JATO paths, selects the first reachable endpoint, and delivers the payload via GET by default or POST when requested. It also supports endpoint override, verbose logging, and payload-only output. The README identifies OpenAM versions through 16.0.5 as affected and 16.0.6 as fixed. Execution is blind, but the request remains open until the launched process exits, allowing timing-based confirmation.
This six-file Python repository implements an operational exploit for the claimed CVE-2026-33439 unsafe Java deserialization issue in OpenIdentityPlatform OpenAM. build.py downloads Maven dependencies, compiles embedded Java sources, constructs a PriorityQueue → Apache Click → Xalan TemplatesImpl gadget chain, and saves it as payload.b64. exploit.py transmits that payload as the jato.clientSession GET query parameter or POST form parameter to pre-authentication JATO endpoints, with endpoint probing, delivery to all known endpoints, optional proxying, optional TLS validation, and an interactive command loop. The generated interactive translet executes attacker-provided cmd header values through /bin/sh and returns output in the HTTP response; blind mode embeds a command at build time for out-of-band execution. verify.py is a local payload-inspection utility that validates Java serialization magic, extracts strings, checks expected gadget-related classes, and scans for selected callback/classloading indicators. No opaque binary payload is committed; the Java payload source is embedded in build.py.
This is a small standalone repository consisting of a usage README and one Python 3 exploit script. exploit.py implements a network-based proof of concept for CVE-2026-33439 affecting OpenAM's pre-authentication handling of the jato.clientSession parameter. It contains an embedded compressed Java serialization payload, verifies its SHA-256 digest and Java stream magic bytes after decoding, then appends the resulting URL-safe Base64 value to a user-provided OpenAM URL. A GET request carries the desired shell command in the cmd header; the stated Click/Xalan gadget executes it and reflects stdout/stderr in the response. The script supports configurable timeout, optional HTTP proxying, and opt-in TLS certificate validation. It validates the supplied URL and rejects CR/LF in commands, but otherwise permits arbitrary single-line shell commands. No external Python dependencies, Java runtime, or JAR files are required on the attack host.
This repository is a compact exploit project for CVE-2026-33439, an unauthenticated Java deserialization RCE in OpenIdentityPlatform OpenAM. It contains 5 files: a Python exploit, a Docker Compose lab for reproducing the issue, a README with vulnerability and usage documentation, plus license and gitignore files. The main exploit file is 02 Exploit/Exploit_CVE_2026_33439.py, which is a standalone Python script rather than a framework module. The exploit’s workflow is: (1) probe likely JATO ViewBean endpoints (/ui/PWResetUserValidation, /ui/PWResetQuestion, /ui/Login), (2) generate and compile a malicious Java EvilTranslet class using attacker-supplied command text, (3) assemble a TemplatesImpl-based serialized gadget chain using OpenAM-bundled libraries, and (4) deliver the serialized payload in the jato.clientSession parameter via HTTP GET or POST to a reachable endpoint. The payload executes arbitrary OS commands through Runtime.getRuntime().exec(), enabling simple command execution, HTTP callback beacons, or reverse shells. The repository also includes 01 Vulnerable/docker-compose.yml, which provisions a vulnerable OpenAM 16.0.5 lab on Tomcat and a separate attacker container. This lab file is not the exploit itself but supports reproduction and testing. The README confirms the target scope as OpenAM versions before 16.0.6 and explains the root cause: jato.clientSession is deserialized without the whitelist protections previously added for jato.pageSession. Overall, this is a real operational exploit PoC with a functional payload path, not merely a detector or write-up. It is operational rather than weaponized because the payload is customizable only through a supplied command string and requires local preparation of specific JAR dependencies.
This repository contains a working exploit for CVE-2026-33439, a pre-authentication Java deserialization RCE in ForgeRock/OpenIdentityPlatform OpenAM. The repo includes both a Nuclei template (CVE-2026-33439.yaml) and a standalone Java PoC source/build setup. Because it is part of a framework, the main exploit file is the Nuclei template, which sends unauthenticated GET requests to OpenAM password-reset UI endpoints with a malicious jato.clientSession parameter and a cmd header. The template uses clusterbomb combinations of base paths (sso, openam, auth, opensso, am) and pages (PWResetUserValidation, PWResetQuestion, PWResetSuccess), executes 'cat /etc/passwd', and confirms exploitation by matching root account output in a 200 response. The accompanying Java PoC shows the exploit structure in detail: it generates a reusable serialized PriorityQueue payload using an Apache Click + Xalan TemplatesImpl gadget chain, encodes it in OpenAM-compatible Base64, and optionally sends it with curl. The embedded translet accesses com.iplanet.jato.RequestManager.getRequestContext(), reads the cmd HTTP header, executes /bin/sh -c <cmd>, and writes command output directly to the HTTP response stream, providing in-band echo-based RCE without DNS/OOB channels. The PoC defaults to proxying through http://127.0.0.1:8080 and supports a --no-proxy option. Repository structure is small and focused: one Nuclei template, one Java source file, a manifest, a build script, and a README. Overall purpose: provide both automated scanning/verification and a standalone exploit implementation for unauthenticated OpenAM RCE via jato.clientSession deserialization.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated Java deserialization remote-code-execution vulnerability in OpenIdentityPlatform OpenAM (<= 16.0.5). An attacker can submit a crafted jato.clientSession value to an exposed JATO ViewBean endpoint, such as the password-reset validation endpoint, to execute arbitrary operating-system commands.
A pre-authentication remote code execution vulnerability affecting OpenAM versions 16.0.5 and earlier.
A pre-authentication remote code execution vulnerability in OpenIdentityPlatform OpenAM caused by unsafe Java deserialization of the jato.clientSession HTTP parameter, allowing unauthenticated arbitrary command execution.
A critical pre-authentication remote code execution vulnerability in OpenIdentityPlatform OpenAM caused by unsafe Java deserialization of the jato.clientSession parameter through an unfiltered deserialization path.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.