Server-Side Request Forgery in OpenAM by ForgeRock
CVE-2026-105122

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 October 2026

What is CVE-2026-105122?

OpenAM versions prior to 16.1.3 are susceptible to a server-side request forgery (SSRF) vulnerability. This vulnerability allows authenticated users with the ability to register or modify OAuth 2.0 clients to exploit an unvalidated jwks_uri. Through this mechanism, attackers can trigger unauthorized fetches from internal resources, including probing for metadata endpoints or accessing local files. This could also lead to denial of service by exhausting request threads, posing significant risks to confidentiality and availability.

Affected Version(s)

OpenAM 0 < 16.1.3

OpenAM 16.1.3

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

arpitjain099
santhreal
alex-sc
jamesbishup
ayhambashtawi2-lang
maximthomas
tsujiguchitky
.