Unauthenticated Arbitrary Class Instantiation Vulnerability in OpenAM by ForgeRock
CVE-2026-105115
8.8HIGH
What is CVE-2026-105115?
OpenAM versions prior to 16.1.3 are susceptible to a vulnerability that allows unauthenticated remote attackers to instantiate arbitrary classes via the legacy JAX-RPC SOAP interface. By exploiting this flaw, attackers can send specially crafted SOAP requests to the /jaxrpc/* endpoint using an unverified session identifier and a designated class name. This could lead to crashes, classpath probing, or potential remote code execution through the use of gadget chains.
Affected Version(s)
OpenAM 0 < 16.1.3
OpenAM 16.1.3
