CVE-2026-105119: OpenAM before 16.1.3 PKCE Enforcement Bypass via OAuth 2.0 Hybrid Flows

Published Oct 3, 2026
·
Updated

OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose responsetype is exactly code, so codes issued through OpenID Connect hybrid flows (code token, code idtoken, code token idtoken) carry no bound challenge. An attacker who intercepts such a code can redeem it for a public client's tokens with any non-empty codeverifier.

Affected Software

1 affected component
ForgeRock OpenAM<16.1.3

Event History

Oct 3, 2026
CVE Published
via MITRE·12:14 PM
Data Sourced
via MITRE·12:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Nov 17, 58725
Event
via NVD·05:34 PM

Frequently Asked Questions

1

Which deployments are exposed?

Deployments running OpenAM before 16.1.3 are exposed when they issue authorization codes to public OAuth 2.0 clients through OpenID Connect hybrid response types: code token, code id_token, or code token id_token.

2

What must an attacker do to exploit this issue?

The attacker must intercept an authorization code issued through an affected hybrid flow. They can then redeem that code for the public client's tokens using any non-empty code_verifier.

3

How can I determine whether my environment is affected?

Check whether the OpenAM version is earlier than 16.1.3 and whether clients use the affected OpenID Connect hybrid response types. PKCE enforcement applied only when response_type was exactly code, so hybrid-flow codes did not have a bound challenge.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203