CVE-2026-105117
published 2026-10-03CVE-2026-105117: OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the…
PriorityP433medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.16%
4.7th percentile
OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json/{realm}/users. Attackers can supply subject and message fields to send phishing mail from the organisation's configured From address, or abuse register as a relay to arbitrary recipients.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openidentityplatform | openam | < 16.1.3 | 16.1.3 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenIdentityPlatform OpenAM up to 16.1.2 Email Notification subject/message injection
vuldb·2026-10-03·CVSS 6.1
CVE-2026-105117 [MEDIUM] OpenIdentityPlatform OpenAM up to 16.1.2 Email Notification subject/message injection
A vulnerability was found in OpenIdentityPlatform OpenAM up to 16.1.2. It has been rated as critical. Affected is an unknown function of the component Email Notification. The manipulation of the argument subject/message leads to injection.
This vulnerability is uniquely identified as CVE-2026-105117. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
GHSA
OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json/
ghsa_unreviewed·2026-10-03
CVE-2026-105117 [MEDIUM] CWE-20 OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json/
OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json/{realm}/users. Attackers can supply subject and message fields to send phishing mail from the organisation's configured From address, or abuse register as a relay to arbitrary recipients.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-10-03
Published