CVE-2026-105115: OpenAM before 16.1.3 Unauthenticated Arbitrary Class Instantiation via JAX-RPC Interface
OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/ with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadget chains.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
ForgeRock OpenAM deployments before version 16.1.3 are affected where the legacy JAX-RPC SOAP interface is reachable at /jaxrpc/*. The issue can be exploited remotely over the network.
Does an attacker need credentials or a valid session?
No. The vulnerable interface accepts SOAP requests with an unverified session identifier, so authentication and a valid session are not required.
What impact can exploitation have?
An attacker can choose classes to load, which can crash the server or probe the application classpath. The issue may also enable code execution if usable gadget chains are present.
What should be prioritized for remediation?
Upgrade OpenAM to version 16.1.3 or later. Until upgrading is possible, restrict network access to the legacy /jaxrpc/* SOAP interface to reduce exposure.