CVE-2026-105117: OpenAM before 16.1.3 Email Content Injection via Users REST Self-Service Actions
OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json/{realm}/users. Attackers can supply subject and message fields to send phishing mail from the organisation's configured From address, or abuse register as a relay to arbitrary recipients.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenAMto a version that resolves this vulnerability.Fixed in 16.1.3
Event History
Frequently Asked Questions
Who is exposed to this issue?
Organisations running ForgeRock OpenAM before 16.1.3 are exposed where the users REST self-service endpoint is reachable and the forgotPassword or register actions can send notification email. Unauthenticated attackers can use these actions.
What does an attacker need to exploit it?
The attacker needs network access to /json/{realm}/users and must be able to invoke the forgotPassword or register self-service actions. No authentication is required, but exploitation involves user interaction because the attack delivers phishing-style email.
What can an attacker do with the vulnerable actions?
An attacker can supply subject and message fields to control notification email wording and send messages from the organisation's configured From address. The register action can also be abused as a relay to arbitrary recipients.
What should be done if an immediate upgrade is not possible?
Restrict access to the affected /json/{realm}/users self-service actions, particularly forgotPassword and register, to prevent unauthenticated use. This may require disabling or limiting those self-service workflows until OpenAM is upgraded to 16.1.3 or later.