2026-10-03 12:14CVE-2026-105116VulnCheck
PUBLISHED5.2CWE-79

OpenAM before 16.1.3 Latent XSS in SAML Load-Balancer Cookie Bounce Page

OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-balancer cookie bounce auto-submit page. If reachable with cookieHashRedirectEnabled set, crafted requests could execute script in the OpenAM origin, though an unrelated HTTP 500 failure prevents exploitation in released versions.

Problem type

Affected products

OpenIdentityPlatform

OpenAM

< 16.1.3 - AFFECTED

16.1.3 - UNAFFECTED

OpenAM

< 16.1.3 - AFFECTED

16.1.3 - UNAFFECTED

OpenAM

< 16.1.3 - AFFECTED

16.1.3 - UNAFFECTED

References

GitHub Security Advisories

GHSA-wxcf-pvf2-p2h6

OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message,...

https://github.com/advisories/GHSA-wxcf-pvf2-p2h6

OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-balancer cookie bounce auto-submit page. If reachable with cookieHashRedirectEnabled set, crafted requests could execute script in the OpenAM origin, though an unrelated HTTP 500 failure prevents exploitation in released versions.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-105116
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-105116",
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "dateUpdated": "2026-10-03T12:14:41.631Z",
    "dateReserved": "2026-10-03T12:04:36.964Z",
    "datePublished": "2026-10-03T12:14:41.631Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck",
        "dateUpdated": "2026-10-03T12:14:41.631Z"
      },
      "datePublic": "2026-09-18T00:00:00.000Z",
      "title": "OpenAM before 16.1.3 Latent XSS in SAML Load-Balancer Cookie Bounce Page",
      "descriptions": [
        {
          "lang": "en",
          "value": "OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-balancer cookie bounce auto-submit page. If reachable with cookieHashRedirectEnabled set, crafted requests could execute script in the OpenAM origin, though an unrelated HTTP 500 failure prevents exploitation in released versions."
        }
      ],
      "affected": [
        {
          "vendor": "OpenIdentityPlatform",
          "product": "OpenAM",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "semver",
              "lessThan": "16.1.3"
            },
            {
              "version": "16.1.3",
              "status": "unaffected",
              "versionType": "semver"
            }
          ]
        },
        {
          "vendor": "OpenIdentityPlatform",
          "product": "OpenAM",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "semver",
              "lessThan": "16.1.3"
            },
            {
              "version": "16.1.3",
              "status": "unaffected",
              "versionType": "semver"
            }
          ]
        },
        {
          "vendor": "OpenIdentityPlatform",
          "product": "OpenAM",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "semver",
              "lessThan": "16.1.3"
            },
            {
              "version": "16.1.3",
              "status": "unaffected",
              "versionType": "semver"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
              "cweId": "CWE-79",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-v796-mg6j-9c5m",
          "name": "GitHub Security Advisory (GHSA-v796-mg6j-9c5m)",
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/openam-before-16.1.3-latent-xss-in-saml-load-balancer-cookie-bounce-page",
          "name": "VulnCheck Advisory: OpenAM before 16.1.3 Latent XSS in SAML Load-Balancer Cookie Bounce Page",
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS"
        },
        {
          "format": "CVSS",
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "scope": "CHANGED",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "availabilityImpact": "NONE",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM"
          }
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "santhreal",
          "type": "reporter"
        },
        {
          "lang": "en",
          "value": "maximthomas",
          "type": "finder"
        },
        {
          "lang": "en",
          "value": "tsujiguchitky",
          "type": "finder"
        }
      ]
    }
  }
}