Description
OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe internal hosts, metadata endpoints or local files, or exhaust request threads for denial of service.
Published: 2026-10-03
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Server‑Side Request Forgery allowing internal resource access
Action: Patch
AI Analysis

Impact

OpenAM before version 16.1.3 contains an SSRF flaw that allows an attacker who can register or modify OAuth 2.0 clients to force the server to fetch arbitrary resources via an unvalidated jwks_uri. The vulnerability is exploitable during client‑authentication and ID‑token validation, enabling the attacker to probe internal hosts, metadata endpoints, local files, or exhaust request threads, potentially exposing internal information or causing denial of service. The likely attack vector is the OAuth client registration or modification flow, as the description indicates attackers can trigger unauthenticated fetches through these operations.

Affected Systems

The affected product is OpenIdentityPlatform OpenAM. All releases prior to version 16.1.3 are vulnerable; no releases beyond 16.1.3 are known to be affected.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk. Because an EPSS score is not available and the vulnerability is not listed in CISA KEV, there is no publicly documented exploitation evidence at this time. Based on the description, it is inferred that an attacker with the ability to register or modify OAuth clients can trigger unauthenticated internal requests or cause service disruption, which suggests that the exploitation risk could be significant in environments exposing client registration to untrusted users.

Generated by OpenCVE AI on October 3, 2026 at 15:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest OpenAM release (16.1.3 or newer) to remove the SSRF flaw.
  • Restrict OAuth client registration and modification to trusted administrators and validate jwks_uri values to prevent malicious input.
  • Deploy outbound network filtering or firewall rules to block OpenAM from reaching internal resources unless explicitly allowed.

Generated by OpenCVE AI on October 3, 2026 at 15:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe internal hosts, metadata endpoints or local files, or exhaust request threads for denial of service.
Title OpenAM before 16.1.3 SSRF via OpenID Connect Client jwks_uri
First Time appeared Openidentityplatform
Openidentityplatform openam
Weaknesses CWE-918
CPEs cpe:2.3:a:openidentityplatform:openam:*:*:*:*:*:*:*:*
Vendors & Products Openidentityplatform
Openidentityplatform openam
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-03T12:14:45.551Z

Reserved: 2026-10-03T12:05:26.755Z

Link: CVE-2026-105122

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T14:16:39.140

Modified: 2026-10-03T14:16:39.140

Link: CVE-2026-105122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T16:00:14Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)