Description
OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadget chains.
Published: 2026-10-03
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Unauthenticated arbitrary class instantiation via SOAP
Action: Patch Immediately
AI Analysis

Impact

OpenAM before version 16.1.3 allows an attacker to trigger arbitrary class instantiation by sending specially crafted SOAP requests to the legacy JAX‑RPC interface. The vulnerability is a misuse of the class loader that does not enforce authentication, enabling an attacker to load electively chosen classes without credentials. The impact ranges from server crashes and class‑path enumeration to potential code execution if vulnerable gadget chains are present. The weakness is categorized as CWE‑306, reflecting an insecure fallback to unauthenticated access.

Affected Systems

The affected product is OpenIdentityPlatform’s OpenAM, all releases prior to 16.1.3. No specific sub‑product version information was provided beyond the overall product name, but any deployment of OpenAM that has not applied the 16.1.3 patch may be vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates a high‑severity vulnerability with the potential for remote exploitation. The EPSS score is not available, so the real‑world exploitation probability cannot be quantified, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers would need to compose a valid SOAP request targeting the /jaxrpc/* endpoint and provide an unverified session identifier; if successful, the server could be coerced into loading arbitrary classes, leading to crashes, inventory gathering, or, with suitable gadget chains, arbitrary code execution. The lack of authentication and the remote nature of the flaw make this an attractive target for automated attackers.

Generated by OpenCVE AI on October 3, 2026 at 15:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenAM to version 16.1.3 or later to fully remediate the vulnerability
  • Restrict or disable the legacy JAX‑RPC SOAP interface by blocking access to /jaxrpc/ endpoints or enforcing authentication before class usage
  • Continuously monitor server logs for unexpected SOAP requests and verify that no unauthenticated class instantiation attempts occur

Generated by OpenCVE AI on October 3, 2026 at 15:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadget chains.
Title OpenAM before 16.1.3 Unauthenticated Arbitrary Class Instantiation via JAX-RPC Interface
First Time appeared Openidentityplatform
Openidentityplatform openam
Weaknesses CWE-306
CPEs cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*
Vendors & Products Openidentityplatform
Openidentityplatform openam
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-03T12:14:40.894Z

Reserved: 2026-10-03T12:04:36.964Z

Link: CVE-2026-105115

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T14:16:38.110

Modified: 2026-10-03T14:16:38.110

Link: CVE-2026-105115

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T15:30:19Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function