Reflected XSS Vulnerability in OpenAM by OpenIdentityPlatform
CVE-2026-105114
5.3MEDIUM
What is CVE-2026-105114?
OpenAM prior to version 16.1.3 is susceptible to a reflected cross-site scripting (XSS) vulnerability. This security flaw permits unauthenticated attackers to craft specific parameters that are rendered unencoded on the OAuth2 authorization error page. By exploiting this vulnerability, attackers can deceive victims into clicking on a manipulated '/oauth2/authorize' link. Such actions could enable the execution of arbitrary JavaScript code in the OpenAM context, potentially leading to session hijacking or redirection to malicious phishing websites.
Affected Version(s)
OpenAM 0 < 16.1.3
OpenAM 16.1.3
