CVE-2026-105118
Last modified
CVE-2026-105118 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust..
Description
OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| OpenIdentityPlatform | OpenAM | < 16.1.3 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-105118?
How severe is CVE-2026-105118?
How do I fix CVE-2026-105118?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-105112Nezha from 1.8.0 before 2.3.13 contains a lock-order inversi…5.3
- CVE-2026-105113Nezha Dashboard from 1.8.0 before 2.3.13 contains an imprope…6.5
- CVE-2026-105114OpenAM before 16.1.3 contains a reflected cross-site scripti…6.1
- CVE-2026-105115OpenAM before 16.1.3 contains an unauthenticated arbitrary c…8.6
- CVE-2026-105116OpenAM before 16.1.3 contains a latent cross-site scripting …6.1
- CVE-2026-105117OpenAM before 16.1.3 contains an email content injection vul…6.1
- CVE-2026-105119OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforc…6.8
- CVE-2026-10512The X25519 x86_64 assembly implementation fails to clear the…7.5
- CVE-2026-105120OpenAM before 16.1.3 contains an authorization bypass vulner…4.9
- CVE-2026-105121OpenAM before 16.1.3 contains an improper authorization vuln…4.9
- CVE-2026-105122OpenAM before 16.1.3 contains a server-side request forgery …5.4
- CVE-2026-105123W (vincent-peugnet/wcms) through 3.18.0 contains a remote co…8.8
Are you affected by CVE-2026-105118?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
