Cross-Site Scripting Vulnerability in OpenAM by Forgerock
CVE-2026-105116

5.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 October 2026

What is CVE-2026-105116?

An open vulnerability exists in OpenAM prior to version 16.1.3 that allows for a cross-site scripting (XSS) attack. This issue arises from the mishandling of SAML messages, relay state, and target URLs which are inserted unencoded into the load-balancer cookie bounce auto-submit page. If the cookieHashRedirectEnabled setting is activated, attackers could potentially craft requests to inject malicious scripts into the OpenAM origin. However, an unrelated HTTP 500 error in released versions of OpenAM limits the ability to exploit this vulnerability.

Affected Version(s)

OpenAM 0 < 16.1.3

OpenAM 0 < 16.1.3

OpenAM 0 < 16.1.3

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
maximthomas
tsujiguchitky
.