Description
Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource and wap/authorize.ftl without HTML escaping. An attacker can induce a user with an active OpenAM session to follow a crafted authorization link and execute JavaScript in the OpenAM origin, enabling session or cookie theft, CSRF-token disclosure, and actions with the victim's privileges. At least one registered OAuth2 client is required, but the attacker does not need to control that client. This issue is fixed in version 16.1.2.
Published: 2026-09-15
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (XSS) that can lead to session or cookie theft, CSRF‑token disclosure, and execution of privileged actions
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a classic reflected XSS flaw (CWE‑79) that occurs within OpenAM’s OAuth2 authorize endpoint when the display=wap consent page renders request‑derived values through the ConsentRequiredResource and wap/authorize.ftl templates without performing HTML escaping. An attacker can craft a malicious authorization request that, when a user with an active OpenAM session clicks the link, causes the OpenAM origin to execute arbitrary JavaScript. This can lead to session or cookie theft, disclosure of CSRF tokens, or execution of privileged actions on behalf of the victim. The flaw is present in OpenAM versions from 13.0.0 up through, but not including, 16.1.2, and it has been fixed in 16.1.2.

Affected Systems

OpenIdentityPlatform’s OpenAM product is affected. All releases from 13.0.0 up to but not including 16.1.2 contain the flaw. An attacker needs at least one registered OAuth2 client, but does not have to control that client. The issue is fixed in OpenAM 16.1.2.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity. The EPSS score of less than 1% shows a very low probability of exploitation at the time of assessment, and the vulnerability is not currently listed in the CISA KEV catalog. Attacks would likely require a user to click a malicious link, making social engineering a necessary component. Given these factors, the overall risk remains moderate but warrants prompt remediation.

Generated by OpenCVE AI on September 17, 2026 at 18:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenAM to version 16.1.2 or later to apply the vendor’s fix for the reflected XSS flaw
  • Disable or remove any OAuth2 clients that are not required to reduce the attack surface for crafted authorization requests
  • Configure the web server to enforce a strict Content Security Policy and disable inline scripting to mitigate the impact if an XSS remains

Generated by OpenCVE AI on September 17, 2026 at 18:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vqxv-6xrh-49cp OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page
History

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Openidentityplatform
Openidentityplatform openam
Vendors & Products Openidentityplatform
Openidentityplatform openam

Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource and wap/authorize.ftl without HTML escaping. An attacker can induce a user with an active OpenAM session to follow a crafted authorization link and execute JavaScript in the OpenAM origin, enabling session or cookie theft, CSRF-token disclosure, and actions with the victim's privileges. At least one registered OAuth2 client is required, but the attacker does not need to control that client. This issue is fixed in version 16.1.2.
Title OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Openidentityplatform Openam
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T17:48:37.357Z

Reserved: 2026-07-13T18:37:08.487Z

Link: CVE-2026-62280

cve-icon Vulnrichment

Updated: 2026-09-16T17:48:34.678Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T10:17:05.957

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-62280

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')