Open Redirect Vulnerability in OpenAM by OpenIdentityPlatform
CVE-2026-105118

2.3LOW

Key Information:

Status
Vendor
CVE Published:
3 October 2026

What is CVE-2026-105118?

OpenAM versions prior to 16.1.3 are susceptible to an open redirect vulnerability. By exploiting this flaw, unauthenticated attackers can manipulate the id_token_hint parameter when accessing the /oauth2/connect/endSession endpoint. This manipulation allows them to redirect users to untrusted URIs by providing crafted hints that reference any realm client. Such redirects take advantage of the trust users place in the OpenAM domain, creating potential phishing opportunities that compromise user data and security.

Affected Version(s)

OpenAM 0 < 16.1.3

OpenAM 16.1.3

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rockmelodies
santhreal
maximthomas
tsujiguchitky
.