CVE-2026-105114: OpenAM before 16.1.3 Reflected XSS via OAuth2 Authorization Error Page
OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject script by supplying crafted parameters rendered unencoded on the OAuth2 authorization error page. Attackers can lure victims to a crafted /oauth2/authorize link with repeated parameters to run JavaScript in the OpenAM origin, acting within existing sessions or redirecting to phishing pages.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
OpenAM deployments running a version before 16.1.3 are affected. The attacker does not need to authenticate, but exploitation requires a victim to visit a crafted OAuth2 authorization URL.
What must an attacker do to exploit it?
An attacker supplies crafted repeated parameters in a /oauth2/authorize link that causes an OAuth2 authorization error page to render attacker-controlled content without encoding. They must convince a victim to open that link.
What is the likely impact if exploitation succeeds?
The injected JavaScript runs in the OpenAM origin. It can act within the victim's existing OpenAM session or redirect the victim to a phishing page.
Are users affected without interacting with an attacker-controlled link?
The provided information indicates user interaction is required. Exploitation depends on luring a victim to the crafted /oauth2/authorize URL.