CVE-2026-105117: OpenAM before 16.1.3 Email Content Injection via Users REST Self-Service Actions

Published Oct 3, 2026
·
Updated

OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json/{realm}/users. Attackers can supply subject and message fields to send phishing mail from the organisation's configured From address, or abuse register as a relay to arbitrary recipients.

Affected Software

1 affected component
ForgeRock OpenAM<16.1.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenAM to a version that resolves this vulnerability.

    Fixed in 16.1.3

Event History

Oct 3, 2026
CVE Published
via MITRE·12:14 PM
Data Sourced
via MITRE·12:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Organisations running ForgeRock OpenAM before 16.1.3 are exposed where the users REST self-service endpoint is reachable and the forgotPassword or register actions can send notification email. Unauthenticated attackers can use these actions.

2

What does an attacker need to exploit it?

The attacker needs network access to /json/{realm}/users and must be able to invoke the forgotPassword or register self-service actions. No authentication is required, but exploitation involves user interaction because the attack delivers phishing-style email.

3

What can an attacker do with the vulnerable actions?

An attacker can supply subject and message fields to control notification email wording and send messages from the organisation's configured From address. The register action can also be abused as a relay to arbitrary recipients.

4

What should be done if an immediate upgrade is not possible?

Restrict access to the affected /json/{realm}/users self-service actions, particularly forgotPassword and register, to prevent unauthenticated use. This may require disabling or limiting those self-service workflows until OpenAM is upgraded to 16.1.3 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203