CVE-2026-105116: Openidentityplatform Openam
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-balancer cookie bounce auto-submit page. If reachable with cookieHashRedirectEnabled set, crafted requests could execute script in the OpenAM origin, though an unrelated HTTP 500 failure prevents exploitation in released versions.
Affected products
- Openidentityplatform Openam: before 16.1.3 (fixed in 16.1.3)
Published 2026-10-03. Last modified 2026-10-06.