Cross-Site Scripting Vulnerability in OpenAM by Forgerock
CVE-2026-105116
5.1MEDIUM
What is CVE-2026-105116?
An open vulnerability exists in OpenAM prior to version 16.1.3 that allows for a cross-site scripting (XSS) attack. This issue arises from the mishandling of SAML messages, relay state, and target URLs which are inserted unencoded into the load-balancer cookie bounce auto-submit page. If the cookieHashRedirectEnabled setting is activated, attackers could potentially craft requests to inject malicious scripts into the OpenAM origin. However, an unrelated HTTP 500 error in released versions of OpenAM limits the ability to exploit this vulnerability.
Affected Version(s)
OpenAM 0 < 16.1.3
OpenAM 0 < 16.1.3
OpenAM 0 < 16.1.3
