OAuth2 Provider PKCE Bypass in OpenAM Affects OpenIdentityPlatform
CVE-2026-105119
What is CVE-2026-105119?
A vulnerability in OpenAM versions prior to 16.1.3 allows an attacker to exploit OAuth2 hybrid flows due to inadequate enforcement of PKCE (Proof Key for Code Exchange) for authorization requests. Specifically, the OAuth2 PKCE challenges are only enforced for requests with a response_type of 'code'. Consequently, authorization codes generated using hybrid flows (such as code token, code id_token, or code token id_token) lack a required bound challenge. This oversight means that an attacker intercepting such codes can potentially redeem them for tokens associated with public clients by using any non-empty code_verifier, posing a significant risk to applications using affected versions of OpenAM.
Affected Version(s)
OpenAM 0 < 16.1.3
OpenAM 16.1.3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
