Cross-Site Scripting Vulnerability in OpenAM Access Management Solution
CVE-2026-44793
7HIGH
What is CVE-2026-44793?
An identified vulnerability in OpenAM allows an unauthenticated attacker to leverage crafted requests to manipulate user-supplied parameters in the SAML2 cluster cookie-hash redirect path. This security issue occurs due to inconsistent encoding of parameters when rendered into HTML, which can lead to script execution within the OpenAM origin, potentially compromising user data and application integrity. The vulnerability is addressed in version 16.1.1.
Affected Version(s)
OpenAM < 16.1.1
