CVE-2026-105115
published 2026-10-03CVE-2026-105115: OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers…
PriorityP263high8.6CVSS 3.1
AVNACLPRNUINSUCLILAH
EPSS
0.46%
37.9th percentile
OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadget chains.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openidentityplatform | openam | < 16.1.3 | 16.1.3 |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenIdentityPlatform OpenAM up to 16.1.2 Legacy JAX-RPC SOAP Interface access control
vuldb·2026-10-03·CVSS 8.6
CVE-2026-105115 [HIGH] OpenIdentityPlatform OpenAM up to 16.1.2 Legacy JAX-RPC SOAP Interface access control
A vulnerability has been found in OpenIdentityPlatform OpenAM up to 16.1.2 and classified as critical. The affected element is an unknown function of the component Legacy JAX-RPC SOAP Interface. This manipulation causes improper access controls.
This vulnerability appears as CVE-2026-105115. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
GHSA
OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication.
ghsa_unreviewed·2026-10-03
CVE-2026-105115 [HIGH] CWE-306 OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication.
OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadget chains.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-10-03
Published