OAuth2 Provider PKCE Bypass in OpenAM Affects OpenIdentityPlatform
CVE-2026-105119

7.6HIGH

Key Information:

Status
Vendor
CVE Published:
3 October 2026

What is CVE-2026-105119?

A vulnerability in OpenAM versions prior to 16.1.3 allows an attacker to exploit OAuth2 hybrid flows due to inadequate enforcement of PKCE (Proof Key for Code Exchange) for authorization requests. Specifically, the OAuth2 PKCE challenges are only enforced for requests with a response_type of 'code'. Consequently, authorization codes generated using hybrid flows (such as code token, code id_token, or code token id_token) lack a required bound challenge. This oversight means that an attacker intercepting such codes can potentially redeem them for tokens associated with public clients by using any non-empty code_verifier, posing a significant risk to applications using affected versions of OpenAM.

Affected Version(s)

OpenAM 0 < 16.1.3

OpenAM 16.1.3

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

arpitjain099
maximthomas
tsujiguchitky
.