Description
OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject script by supplying crafted parameters rendered unencoded on the OAuth2 authorization error page. Attackers can lure victims to a crafted /oauth2/authorize link with repeated parameters to run JavaScript in the OpenAM origin, acting within existing sessions or redirecting to phishing pages.
Published: 2026-10-03
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

OpenAM versions prior to 16.1.3 contain a reflected cross‑site scripting flaw that allows an unauthenticated attacker to inject malicious script into the OAuth2 authorization error page. The vulnerability arises because specially crafted parameters are included in the page without proper encoding. An attacker can lure a user to a malicious \/oauth2\/authorize link that contains repeated parameters, causing arbitrary JavaScript to execute in the victim’s browser under the OpenAM origin. This can be used to manipulate the user’s session or redirect them to phishing sites, potentially leading to credential theft or illicit account takeover.

Affected Systems

OpenIdentityPlatform’s OpenAM product is affected. All deployments running a version earlier than 16.1.3 are susceptible. The vulnerability is present across all platforms that use the default error handling for OAuth2, regardless of underlying operating system or hosting environment.

Risk and Exploitability

The CVSS score is 5.3, indicating medium severity, and the exploit probability is unknown as its EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs to send a crafted link to a victim; no privileged access is required. The exploit is straightforward, but the impact is limited to the victim’s device, not to the server itself.

Generated by OpenCVE AI on October 3, 2026 at 15:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply an update to OpenAM 16.1.3 or later to eliminate the reflected script rendering.
  • Configure the OAuth2 error handling to HTML‑encode or discard untrusted parameters before displaying them.
  • Verify that redirect URIs do not echo query parameters back to the user and enforce strict validation of all incoming parameters.

Generated by OpenCVE AI on October 3, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject script by supplying crafted parameters rendered unencoded on the OAuth2 authorization error page. Attackers can lure victims to a crafted /oauth2/authorize link with repeated parameters to run JavaScript in the OpenAM origin, acting within existing sessions or redirecting to phishing pages.
Title OpenAM before 16.1.3 Reflected XSS via OAuth2 Authorization Error Page
First Time appeared Openidentityplatform
Openidentityplatform openam
Weaknesses CWE-79
CPEs cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*
Vendors & Products Openidentityplatform
Openidentityplatform openam
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-03T12:14:39.964Z

Reserved: 2026-10-03T12:04:36.964Z

Link: CVE-2026-105114

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T14:16:37.963

Modified: 2026-10-03T14:16:37.963

Link: CVE-2026-105114

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T15:30:19Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')