Description
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect authorization endpoint does not sufficiently encode user-supplied parameters before FormPostResponse.ftl and checkSession.ftl render them into HTML for the form_post response mode. An unauthenticated attacker can induce a user to open a crafted authorization request and execute script in the OpenAM origin. This issue is fixed in version 16.1.1.
Published: 2026-09-15
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a reflected Cross‑Site Scripting flaw in OpenAM's OAuth 2.0 and OpenID Connect authorization endpoint when the form_post response mode is used. Prior to version 16.1.1 the service fails to properly encode user‑supplied parameters such as the state value before rendering the form in FormPostResponse.ftl and checkSession.ftl. An unauthenticated attacker can craft a malicious OAuth request, prompt a victim to visit it, and have script executed in the victim’s browser within the OpenAM origin. The flaw does not affect the server side; the impact consists of client‑side code execution in the victim’s context.

Affected Systems

OpenIdentityPlatform OpenAM versions prior to 16.1.1 are affected; all deployments using the OAuth2/OIDC authorization endpoint with form_post response mode are at risk.

Risk and Exploitability

The CVSS base score of 8.3 indicates high severity; the EPSS score of less than 1% suggests low exploitation probability; the vulnerability is not listed in the CISA KEV catalog; the exploit requires an unauthenticated user to be tricked into opening a malicious OAuth request, so it is a remote client‑side XSS that is easy to construct but needs phishing or social engineering.

Generated by OpenCVE AI on September 17, 2026 at 18:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenAM to version 16.1.1 or later, which contains the fix.
  • If upgrading is not immediately feasible, disable the response_mode=form_post or enforce strict validation/encoding of the state parameter.
  • Implement content security policy and to mitigate the impact of any remaining XSS vectors.

Generated by OpenCVE AI on September 17, 2026 at 18:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-fq9h-c788-fx73 OpenAM has pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)
History

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Openidentityplatform
Openidentityplatform openam
Vendors & Products Openidentityplatform
Openidentityplatform openam

Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect authorization endpoint does not sufficiently encode user-supplied parameters before FormPostResponse.ftl and checkSession.ftl render them into HTML for the form_post response mode. An unauthenticated attacker can induce a user to open a crafted authorization request and execute script in the OpenAM origin. This issue is fixed in version 16.1.1.
Title OpenAM: Pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T14:02:34.668Z

Reserved: 2026-05-05T15:13:47.571Z

Link: CVE-2026-44203

cve-icon Vulnrichment

Updated: 2026-09-17T14:02:30.441Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T10:17:03.510

Modified: 2026-09-23T18:19:19.803

Link: CVE-2026-44203

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')