Description
OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.
Published: 2026-10-03
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: Open Redirect enabling phishing via unverified id_token_hint
Action: Immediate Upgrade
AI Analysis

Impact

OpenAM before version 16.1.3 has a flaw that allows attackers who are not authenticated to trigger a redirect by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Because the supplied token hint is not validated, the system will redirect the user to a post‑logout URI that was registered for the specified realm. An attacker can choose any realm and any registered redirect target, effectively causing the victim to be sent to a malicious site that can be used for phishing or credential theft.

Affected Systems

The affected products are OpenIdentityPlatform OpenAM, all releases prior to 16.1.3. The vulnerability applies to any installation that accepts unverified id_token_hint values for the endSession endpoint. Specific versions are not listed beyond the 16.1.3 cutoff, so all older builds that have not applied subsequent patches are potentially vulnerable.

Risk and Exploitability

The CVSS score of 2.3 reflects a low impact in terms of attacker's privileges, but the exploit is trivial to execute: an unauthenticated user only needs to send a crafted /endSession request with a forged id_token_hint. Because the redirect target is controlled by the attacker, there is no requirement for privileged access, and the risk of phishing and social engineering is amplified by the OpenAM host’s reputation. EPSS data is not available and the vulnerability is not currently listed in the CISA KEV catalog, indicating that while widespread exploitation is not known, the potential for abuse remains.

Generated by OpenCVE AI on October 3, 2026 at 15:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenAM to version 16.1.3 or later, which removes the open redirect flaw.
  • If immediate upgrade is not possible, enforce validation of the id_token_hint parameter so that only recognized, signed tokens are accepted and the redirect URI is strictly limited to registered post‑logout URLs.
  • Disable or restrict unauthenticated access to the /oauth2/connect/endSession endpoint to prevent attackers from freely injecting redirect hints.
  • Monitor application logs for unusual endSession requests and block traffic that contains unexpected id_token_hint values.

Generated by OpenCVE AI on October 3, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.
Title OpenAM before 16.1.3 Open Redirect via Unverified id_token_hint in endSession
First Time appeared Openidentityplatform
Openidentityplatform openam
Weaknesses CWE-347
CPEs cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*
Vendors & Products Openidentityplatform
Openidentityplatform openam
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-03T12:14:43.044Z

Reserved: 2026-10-03T12:04:36.964Z

Link: CVE-2026-105118

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T14:16:38.563

Modified: 2026-10-03T14:16:38.563

Link: CVE-2026-105118

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T15:30:19Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature