Cross-Site Scripting Vulnerability in Open Access Management by OpenIdentity
CVE-2026-44203

8.3HIGH

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-44203?

A vulnerability in Open Access Management prior to version 16.1.1 allows an unauthenticated attacker to exploit insufficient encoding of user-supplied parameters in the OAuth 2.0 and OpenID Connect authorization endpoints. This can lead to the rendering of malicious scripts when users respond to crafted authorization requests, putting their sessions at risk. This issue, which has potential implications for user data and application integrity, has been addressed in version 16.1.1.

Affected Version(s)

OpenAM < 16.1.1

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.