Email Content Injection Vulnerability in OpenAM by ForgeRock
CVE-2026-105117

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 October 2026

What is CVE-2026-105117?

OpenAM versions prior to 16.1.3 are vulnerable to an email content injection flaw. This security issue enables unauthenticated attackers to manipulate the content of notification emails sent during the forgotPassword and register processes. By supplying crafted subject and message fields, attackers can use the organization's configured From address to send phishing emails, potentially deceiving recipients. Additionally, this vulnerability allows attackers to misuse the registration feature as a relay, resulting in emails being sent to arbitrary recipients without proper authorization.

Affected Version(s)

OpenAM 0 < 16.1.3

OpenAM 0 < 16.1.3

OpenAM 16.1.3

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
maximthomas
tsujiguchitky
.