CVE-2026-105114
Received Received - Intake

Reflected XSS in OpenAM OAuth2 Authorization Page

Vulnerability report for CVE-2026-105114, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: VulnCheck

Description

OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject script by supplying crafted parameters rendered unencoded on the OAuth2 authorization error page. Attackers can lure victims to a crafted /oauth2/authorize link with repeated parameters to run JavaScript in the OpenAM origin, acting within existing sessions or redirecting to phishing pages.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
forgerock openam to 16.1.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105114 is a reflected cross-site scripting (XSS) vulnerability in OpenAM versions before 16.1.3. It allows unauthenticated attackers to inject malicious scripts by crafting parameters on the OAuth2 authorization error page. User input is rendered unencoded, enabling JavaScript execution in the OpenAM origin. Victims may be tricked via a specially crafted /oauth2/authorize link with repeated parameters.

Detection Guidance

To detect this vulnerability, monitor network traffic for requests to the /oauth2/authorize endpoint with repeated parameters. Check web server logs for unusual JavaScript execution or unexpected redirects. Use tools like Burp Suite or OWASP ZAP to intercept and inspect OAuth2 authorization requests for unencoded parameters.

Impact Analysis

This vulnerability can lead to session hijacking, where attackers steal active user sessions. It may also redirect victims to phishing pages, enabling credential theft or further exploitation. Attackers can act within existing sessions or manipulate users into executing malicious actions without authentication.

Compliance Impact

This reflected XSS vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Attackers may steal session tokens or inject malicious scripts to exfiltrate data, compromising confidentiality and integrity of user sessions.

Mitigation Strategies

Immediately upgrade OpenAM to version 16.1.3 or later. As a temporary measure, implement a Content-Security-Policy to block inline scripts, restrict access to the /oauth2/authorize endpoint, or deploy a web application firewall to block requests with suspicious characters.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105114. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart