Unauthenticated Arbitrary Class Instantiation Vulnerability in OpenAM by ForgeRock
CVE-2026-105115

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
3 October 2026

What is CVE-2026-105115?

OpenAM versions prior to 16.1.3 are susceptible to a vulnerability that allows unauthenticated remote attackers to instantiate arbitrary classes via the legacy JAX-RPC SOAP interface. By exploiting this flaw, attackers can send specially crafted SOAP requests to the /jaxrpc/* endpoint using an unverified session identifier and a designated class name. This could lead to crashes, classpath probing, or potential remote code execution through the use of gadget chains.

Affected Version(s)

OpenAM 0 < 16.1.3

OpenAM 16.1.3

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
alex-sc
maximthomas
tsujiguchitky
.