CVE-2026-105118 LOW

CVE-2026-105118: OpenAM before 16.1.3 Open Redirect via Unverified id_token_hint in endSession

Vendor Openidentityplatform
Product OpenAM
Weakness CWE-347
Published October 3, 2026
Last update October 3, 2026

CVSS base score

2.3/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction —
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.

Key dates

02Disclosure timeline

October 3, 2026 CVE published

Related vulnerabilities

04Related CVE