CVE-2026-105118: OpenAM before 16.1.3 Open Redirect via Unverified id_token_hint in endSession
OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified idtokenhint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenAMto a version that resolves this vulnerability.Fixed in 16.1.3