CVE-2020-13421: Openiam

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

OpenIAM before 4.2.0.3 has Incorrect Access Control for the Create User, Modify User Permissions, and Password Reset actions.

Affected products

  • Openiam Openiam: before 4.2.0.3 (fixed in 4.2.0.3)

Published 2021-04-06. Last modified 2026-06-17.