CVE-2026-105119
Received Received - Intake

OpenAM OAuth2 PKCE Bypass via Hybrid Flow

Vulnerability report for CVE-2026-105119, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: VulnCheck

Description

OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued through OpenID Connect hybrid flows (code token, code id_token, code token id_token) carry no bound challenge. An attacker who intercepts such a code can redeem it for a public client's tokens with any non-empty code_verifier.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
forgerock openam to 16.1.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenAM before version 16.1.3 has a vulnerability in its PKCE (Proof Key for Code Exchange) enforcement. The system only enforces PKCE for authorization requests using the response type 'code'. However, it fails to apply this enforcement to OAuth 2.0 hybrid flows like 'code token', 'code id_token', or 'code token id_token'. This allows attackers to intercept codes from these hybrid flows and redeem them for tokens without providing the required code verifier.

Detection Guidance

To detect this vulnerability, check OpenAM versions before 16.1.3 and inspect authorization requests for hybrid flows (code token, code id_token, code token id_token). Monitor logs for codes issued without PKCE challenges. Use network traffic analysis to identify intercepted codes being redeemed without a code_verifier.

Impact Analysis

This vulnerability primarily affects public clients such as native and single-page applications. Attackers can intercept authorization codes from hybrid flows and exchange them for tokens without needing additional credentials. For confidential clients, attackers would also need the client's authentication credentials. The impact includes unauthorized token access, potential data breaches, and compromised user sessions.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. GDPR requires protection of personal data, while HIPAA mandates safeguards for protected health information. A breach through this flaw may result in non-compliance, legal penalties, and reputational damage for organizations using vulnerable OpenAM versions.

Mitigation Strategies

Upgrade OpenAM to version 16.1.3 or later. Disable hybrid flows for clients that do not require them. Ensure confidential clients always send a code challenge. Shorten authorization code lifetimes and monitor for hybrid requests missing a code challenge.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105119. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart