CVE-2026-105122
published 2026-10-03CVE-2026-105122: OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM…
PriorityP431medium5.4CVSS 3.1
AVNACLPRLUINSUCLINAL
EPSS
0.23%
12.9th percentile
OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe internal hosts, metadata endpoints or local files, or exhaust request threads for denial of service.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openidentityplatform | openam | < 16.1.3 | 16.1.3 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenIdentityPlatform OpenAM up to 16.1.2 server-side request forgery
vuldb·2026-10-03·CVSS 5.4
CVE-2026-105122 [MEDIUM] OpenIdentityPlatform OpenAM up to 16.1.2 server-side request forgery
A vulnerability classified as problematic has been found in OpenIdentityPlatform OpenAM up to 16.1.2. Impacted is an unknown function. The manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2026-105122. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
GHSA
OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated
ghsa_unreviewed·2026-10-03
CVE-2026-105122 [MEDIUM] CWE-918 OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated
OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe internal hosts, metadata endpoints or local files, or exhaust request threads for denial of service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-10-03
Published