CVE-2026-105116
Received Received - Intake

OpenAM Cross-Site Scripting via SAML Relay State

Vulnerability report for CVE-2026-105116, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: VulnCheck

Description

OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-balancer cookie bounce auto-submit page. If reachable with cookieHashRedirectEnabled set, crafted requests could execute script in the OpenAM origin, though an unrelated HTTP 500 failure prevents exploitation in released versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
forgerock openam to 16.1.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105116 is a latent cross-site scripting (XSS) vulnerability in OpenAM versions before 16.1.3. It involves unencoded SAML messages, relay state, and target URL being placed into the load-balancer cookie bounce auto-submit page. This could allow script execution in the OpenAM origin if the cookieHashRedirectEnabled setting is enabled.

Detection Guidance

This vulnerability is not practically exploitable due to an unrelated HTTP 500 error preventing page rendering. Detection is unnecessary as the vulnerable code path is unreachable in released versions. Check if your OpenAM version is 16.1.3 or later to confirm the fix is applied.

Impact Analysis

The impact is limited because exploitation is prevented in released versions due to an unrelated HTTP 500 error. Even if reachable, it requires a multi-server deployment with a specific non-default system property enabled and a crafted request. The default configuration is not affected.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR or HIPAA as it was not exploitable in released versions due to an unrelated HTTP 500 error. The latent XSS flaw required specific non-default configurations and conditions to potentially execute, which were not met in practice.

Mitigation Strategies

No immediate mitigation is required. Update OpenAM to version 16.1.3 or later to address the latent defect. The default configuration is not affected, and the vulnerability is not exploitable in practice.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105116. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart