Email Content Injection Vulnerability in OpenAM by ForgeRock
CVE-2026-105117
5.3MEDIUM
What is CVE-2026-105117?
OpenAM versions prior to 16.1.3 are vulnerable to an email content injection flaw. This security issue enables unauthenticated attackers to manipulate the content of notification emails sent during the forgotPassword and register processes. By supplying crafted subject and message fields, attackers can use the organization's configured From address to send phishing emails, potentially deceiving recipients. Additionally, this vulnerability allows attackers to misuse the registration feature as a relay, resulting in emails being sent to arbitrary recipients without proper authorization.
Affected Version(s)
OpenAM 0 < 16.1.3
OpenAM 0 < 16.1.3
OpenAM 16.1.3
