Reflected XSS Vulnerability in OpenAM by OpenIdentityPlatform
CVE-2026-105114

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 October 2026

What is CVE-2026-105114?

OpenAM prior to version 16.1.3 is susceptible to a reflected cross-site scripting (XSS) vulnerability. This security flaw permits unauthenticated attackers to craft specific parameters that are rendered unencoded on the OAuth2 authorization error page. By exploiting this vulnerability, attackers can deceive victims into clicking on a manipulated '/oauth2/authorize' link. Such actions could enable the execution of arbitrary JavaScript code in the OpenAM context, potentially leading to session hijacking or redirection to malicious phishing websites.

Affected Version(s)

OpenAM 0 < 16.1.3

OpenAM 16.1.3

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Buggs777
tsujiguchitky
.