Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105118— OpenAM before 16.1.3 Open Redirect via Unverified id_token_hint in endSession

Quick assessment

Affected
OpenIdentityPlatform OpenAM
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenAM 16.1.3 之前的版本存在一个开放重定向漏洞,未身份验证的攻击者可以通过向 /oauth2/connect/endSession 端点提供未经验证的 id_token_hint 参数,重定向用户。攻击者可以在伪造的提示中指定任何领域的客户端,从而将受害者重定向到任何已注册的后登出 URI,这使得攻击者能够利用 OpenAM 主机的可信度进行网络钓鱼攻击。

CVSS 4.7 · Medium

Possible ATT&CK Techniques 1 AI

T1189 · Drive-by Compromise

Affected Version Matrix 2

VendorProduct Version RangeStatus
OpenIdentityPlatform OpenAM < 16.1.3 affected
16.1.3 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105118

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OpenAM before 16.1.3 Open Redirect via Unverified id_token_hint in endSession
Source: CVE Program / CVE List V5
Vulnerability Description
OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
密码学签名的验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OpenIdentityPlatform OpenAM 0 ~ 16.1.3 -

II. Public POCs for CVE-2026-105118

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105118

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-105118 (2)

Same Patch Batch · OpenIdentityPlatform · 2026-10-03 · 9 CVEs total

CVE-2026-105115 8.6 HIGH OpenAM before 16.1.3 Unauthenticated Arbitrary Class Instantiation via JAX-RPC Interface
CVE-2026-105119 6.8 MEDIUM OpenAM before 16.1.3 PKCE Enforcement Bypass via OAuth 2.0 Hybrid Flows
CVE-2026-105117 6.1 MEDIUM OpenAM before 16.1.3 Email Content Injection via Users REST Self-Service Actions
CVE-2026-105114 6.1 MEDIUM OpenAM before 16.1.3 Reflected XSS via OAuth2 Authorization Error Page
CVE-2026-105116 6.1 MEDIUM OpenAM before 16.1.3 Latent XSS in SAML Load-Balancer Cookie Bounce Page
CVE-2026-105122 5.4 MEDIUM OpenAM before 16.1.3 SSRF via OpenID Connect Client jwks_uri
CVE-2026-105120 4.9 MEDIUM OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpoint
CVE-2026-105121 4.9 MEDIUM OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping

IV. Related Vulnerabilities

V. Comments for CVE-2026-105118

No comments yet


Leave a comment