CVE-2026-105117
Received Received - Intake

Email Content Injection in OpenAM

Vulnerability report for CVE-2026-105117, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: VulnCheck

Description

OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json/{realm}/users. Attackers can supply subject and message fields to send phishing mail from the organisation's configured From address, or abuse register as a relay to arbitrary recipients.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
forgerock openam to 16.1.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenAM before version 16.1.3 has an email content injection flaw. Unauthenticated attackers can manipulate notification emails sent via the forgotPassword and register actions on the /json/{realm}/users endpoint. They can control email subject and message fields, enabling phishing emails to be sent from the organization's configured address or using the register function as a mail relay.

Detection Guidance

Check OpenAM version with curl -s http://your-openam-server/openam/version | grep -i version. If version is before 16.1.3, the system is vulnerable. Inspect network traffic for unusual SMTP connections from OpenAM server to external mail servers, especially to unknown recipients.

Impact Analysis

Attackers can send phishing emails that appear to come from your organization, tricking recipients into clicking malicious links or revealing sensitive information. The register action can be abused to send emails to arbitrary recipients, potentially spreading malware or conducting social engineering attacks.

Compliance Impact

This vulnerability could lead to data breaches or unauthorized access, violating GDPR's data protection requirements and HIPAA's security rules. Organizations may face fines or penalties for failing to protect user data from phishing attacks facilitated by this flaw.

Mitigation Strategies

Upgrade OpenAM to version 16.1.3 or later immediately. Disable legacy self-service actions (forgotPassword and register) if not needed. Configure reverse proxy to strip caller-supplied email content. Rate-limit the affected endpoints to reduce abuse.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105117. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart