Description
OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued through OpenID Connect hybrid flows (code token, code id_token, code token id_token) carry no bound challenge. An attacker who intercepts such a code can redeem it for a public client's tokens with any non-empty code_verifier.
Published: 2026-10-03
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: Token issuance bypass leading to potential token theft
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists because OpenAM only applies PKCE enforcement to authorization requests with response_type exactly "code". Hybrid flows such as "code token", "code id_token", or "code token id_token" are exempted, allowing issued codes to be used without a bound challenge. An attacker who intercepts a hybrid flow code can redeem it against a public client using any non‑empty code_verifier and obtain tokens. This can compromise user sessions or grant unauthorized access to protected resources.

Affected Systems

OpenIdentityPlatform’s OpenAM is affected when installed at any version earlier than 16.1.3. No other vendors or products are listed as impacted.

Risk and Exploitability

The CVSS score of 7.6 indicates a high‑severity flaw. The EPSS score is not available, but the lack of listing in the CISA KEV catalog suggests that at present the vulnerability is not widely exploited. The likely attack vector is remote, requiring the ability to observe or capture network traffic to obtain an authorization code from a hybrid flow. Once the code is captured, redemption is straightforward and bypasses PKCE checks entirely. Organizations that enable hybrid OAuth flows with public clients face significant risk if they do not apply the 16.1.3 update or otherwise enforce PKCE for all flow types.

Generated by OpenCVE AI on October 3, 2026 at 15:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenAM to version 16.1.3 or newer, where PKCE enforcement applies to all response_type values including hybrid flows.
  • If an upgrade is not immediately possible, restrict or disable OpenID Connect hybrid flows for public clients, or ensure that the client implements its own PKCE validation before redeeming codes.
  • Apply a network-level interception prevention measure, such as TLS encryption and proper client authentication, to reduce the likelihood that an attacker can capture authentication codes.

Generated by OpenCVE AI on October 3, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued through OpenID Connect hybrid flows (code token, code id_token, code token id_token) carry no bound challenge. An attacker who intercepts such a code can redeem it for a public client's tokens with any non-empty code_verifier.
Title OpenAM before 16.1.3 PKCE Enforcement Bypass via OAuth 2.0 Hybrid Flows
First Time appeared Openidentityplatform
Openidentityplatform openam
Weaknesses CWE-285
CPEs cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*
Vendors & Products Openidentityplatform
Openidentityplatform openam
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-03T12:14:43.643Z

Reserved: 2026-10-03T12:04:36.964Z

Link: CVE-2026-105119

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T14:16:38.710

Modified: 2026-10-03T14:16:38.710

Link: CVE-2026-105119

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T15:30:19Z

Weaknesses