CVE-2026-105118
Received Received - Intake

Open Redirect Vulnerability in OpenAM

Vulnerability report for CVE-2026-105118, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: VulnCheck

Description

OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
forgerock openam to 16.1.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105118 is an open redirect vulnerability in OpenAM versions before 16.1.3. It occurs in the /oauth2/connect/endSession endpoint which accepts an unverified id_token_hint parameter. Attackers can supply a forged hint to redirect users to any registered post-logout URI, enabling phishing attacks that exploit the OpenAM host's trusted domain.

Detection Guidance

To detect this vulnerability, monitor network traffic for requests to the /oauth2/connect/endSession endpoint with an id_token_hint parameter. Check if the endpoint accepts unverified hints and redirects users to arbitrary URIs. Review OpenAM logs for suspicious post-logout redirect attempts or unauthorized realm client manipulations.

Impact Analysis

This vulnerability allows unauthenticated attackers to redirect users to malicious websites by manipulating the post-logout redirect URI. Victims may be tricked into entering credentials or sensitive information on fake pages that appear to be part of the legitimate OpenAM host, leading to potential account compromise or data theft.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling phishing attacks that exploit OpenAM's trusted domain. Unauthorized redirects may lead to unauthorized access to personal data, violating GDPR's data protection principles or HIPAA's safeguards for protected health information.

Mitigation Strategies

Upgrade OpenAM to version 16.1.3 or later to patch the vulnerability. As temporary measures, disable dynamic client registration, review and restrict post-logout URIs, and limit access to the registration endpoint. Monitor for any ongoing exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105118. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart