CVE-2026-105118
published 2026-10-03CVE-2026-105118: OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint…
PriorityP424medium4.7CVSS 3.1
AVNACHPRNUIRSCCLILAN
EPSS
0.10%
0.8th percentile
OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openidentityplatform | openam | < 16.1.3 | 16.1.3 |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv4.02.3LOWCVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint
ghsa_unreviewed·2026-10-03
CVE-2026-105118 [LOW] CWE-347 OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint
OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.
VulDB
OpenIdentityPlatform OpenAM up to 16.1.2 Session Endpoint endSession id_token_hint redirect
vuldb·2026-10-03·CVSS 4.7
CVE-2026-105118 [MEDIUM] OpenIdentityPlatform OpenAM up to 16.1.2 Session Endpoint endSession id_token_hint redirect
A vulnerability identified as problematic has been detected in OpenIdentityPlatform OpenAM up to 16.1.2. Affected by this issue is some unknown functionality of the file /oauth2/connect/endSession of the component Session Endpoint. This manipulation of the argument id_token_hint causes open redirect.
The identification of this vulnerability is CVE-2026-105118. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-10-03
Published