Description
OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json/{realm}/users. Attackers can supply subject and message fields to send phishing mail from the organisation's configured From address, or abuse register as a relay to arbitrary recipients.
Published: 2026-10-03
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Email content injection allowing attackers to send phishing or relay messages from the server's configured From address
Action: Patch Update
AI Analysis

Impact

The vulnerability is an email content injection flaw in OpenAM, classified as CWE‑20, that allows an unauthenticated attacker to supply arbitrary subject and message fields on the forgotPassword and register endpoints exposed at /json/{realm}/users. By controlling these fields, the attacker can send phishing emails or use the service as an email relay, sending mail from the server’s configured From address to arbitrary recipients. This can lead to credential theft, spoofing, and other social‑engineering attacks, compromising the confidentiality and integrity of the organization’s communications.

Affected Systems

The affected product is OpenIdentityPlatform OpenAM. All releases prior to version 16.1.3 are vulnerable, including 16.1.2 and earlier revisions.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the probability of exploitation is not quantified (EPSS not available). The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw without authentication by sending specially crafted JSON to the mentioned REST endpoints, which are reachable from the network where the OpenAM server is exposed.

Generated by OpenCVE AI on October 3, 2026 at 15:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to OpenAM 16.1.3 or later, which includes the fix for email content injection.
  • Restrict access to the /json/{realm}/users endpoint, limiting it to trusted networks or enforcing authentication before permitting the forgotPassword or register actions.
  • Sanitize and validate any user‑supplied subject or message parameters, ensuring they cannot inject arbitrary email content or alter the From address.
  • Consider disabling the forgotPassword and register REST endpoints if they are not required for your deployment.

Generated by OpenCVE AI on October 3, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json/{realm}/users. Attackers can supply subject and message fields to send phishing mail from the organisation's configured From address, or abuse register as a relay to arbitrary recipients.
Title OpenAM before 16.1.3 Email Content Injection via Users REST Self-Service Actions
First Time appeared Openidentityplatform
Openidentityplatform openam
Weaknesses CWE-20
CPEs cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*
Vendors & Products Openidentityplatform
Openidentityplatform openam
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-03T12:14:42.310Z

Reserved: 2026-10-03T12:04:36.964Z

Link: CVE-2026-105117

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T14:16:38.413

Modified: 2026-10-03T14:16:38.413

Link: CVE-2026-105117

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T15:30:19Z

Weaknesses
  • CWE-20

    Improper Input Validation