CVE-2026-105119: Openidentityplatform Openam
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued through OpenID Connect hybrid flows (code token, code id_token, code token id_token) carry no bound challenge. An attacker who intercepts such a code can redeem it for a public client's tokens with any non-empty code_verifier.
Affected products
- Openidentityplatform Openam: before 16.1.3 (fixed in 16.1.3)
Published 2026-10-03. Last modified 2026-10-06.