Description
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non-default clustered configuration inconsistently encode user-supplied parameters rendered into HTML in the SAML2 cluster cookie-hash redirect path. An unauthenticated attacker can induce a user to follow a crafted request and execute script in the OpenAM origin. This issue is fixed in version 16.1.1.
Published: 2026-09-15
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (XSS)
Action: Immediate Patch
AI Analysis

Impact

A flaw in OpenAM before version 16.1.1 allows an unauthenticated attacker to craft a URL that causes the server to render user‑supplied parameters inconsistent with encoding rules in the SAML2 cluster cookie‑hash redirect path. When a victim follows the crafted link, arbitrary JavaScript is executed in the OpenAM origin, giving the attacker the ability to run scripts in the user’s browser. The weakness is a classic reflected XSS (CWE‑79) and, according to the description, results only in script execution, not additional privileges or services.

Affected Systems

OpenIdentityPlatform's OpenAM product is vulnerable when a non‑default clustered configuration is used in any release prior to 16.1.1. The fix was included in the 16.1.1 release; all installations older than that version that use the affected federation endpoints remain at risk.

Risk and Exploitability

The CVSS score of 7 indicates high severity. The EPSS score is below 1 %, implying that exploitation is considered unlikely, and the vulnerability does not appear in the CISA KEV catalog. The attack requires the victim to be directed to a malicious URL and to click it; the attacker does not need credentials but can inject code that runs in the victim’s browser.

Generated by OpenCVE AI on September 17, 2026 at 18:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the OpenAM installation to version 16.1.1 or later to receive the official fix.
  • If an upgrade is not immediately possible, block or remove federation endpoints that expose the SAML2 cluster cookie‑hash redirect path from public access.
  • Ensure that all user‑supplied parameters destined for the SAML2 cluster cookie‑hash redirect path are correctly HTML‑escaped before rendering them in the response.

Generated by OpenCVE AI on September 17, 2026 at 18:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-fhrq-3gmx-p879 OpenAM SAML2 Cluster Cookie-Hash-Redirect Path has Pre-authentication Reflected XSS via `FSUtils.postToTarget`
History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Openidentityplatform
Openidentityplatform openam
Vendors & Products Openidentityplatform
Openidentityplatform openam

Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non-default clustered configuration inconsistently encode user-supplied parameters rendered into HTML in the SAML2 cluster cookie-hash redirect path. An unauthenticated attacker can induce a user to follow a crafted request and execute script in the OpenAM origin. This issue is fixed in version 16.1.1.
Title OpenAM: Pre-authentication Reflected XSS in SAML2 Cluster Cookie-Hash-Redirect Path via `FSUtils.postToTarget`
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T13:53:25.764Z

Reserved: 2026-05-07T19:20:44.692Z

Link: CVE-2026-44793

cve-icon Vulnrichment

Updated: 2026-09-15T13:25:15.404Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T10:17:03.717

Modified: 2026-09-23T18:21:42.327

Link: CVE-2026-44793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')