CVE-2026-44203
moderateReflected XSS in OpenAM OAuth 2.0/OIDC Authorization Endpoint (pre-16.1.1)
Open Access Management (OpenAM) versions prior to 16.1.1 fail to properly encode user-supplied parameters before the FormPostResponse.ftl and checkSession.ftl FreeMarker templates render them into HTML for the OAuth 2.0/OpenID Connect form_post response mode. An unauthenticated attacker can craft a malicious authorization request and induce a victim to open it, causing attacker-controlled script to execute in the victim's browser under the OpenAM origin. Because OpenAM is an identity provider, successful exploitation can let the attacker hijack sessions, steal tokens or credentials, or tamper with authentication flows on the affected deployment. Any organization self-hosting OpenAM older than 16.1.1 that exposes the OAuth 2.0/OIDC authorization endpoint is affected. The flaw is fixed in version 16.1.1; there is no known public proof of concept and the issue is not on the CISA KEV catalog.
What to do: Upgrade OpenAM to version 16.1.1 or later, which fixes the encoding flaw in the form_post response templates. Until the upgrade is complete, consider blocking or restricting the form_post response mode for OAuth 2.0/OIDC clients, and apply WAF rules to filter HTML/script payloads in authorization request parameters. Review authorization endpoint logs for crafted requests containing markup in state, redirect_uri, or other user-supplied parameters that could indicate exploitation attempts.
| OpenIdentityPlatform / OpenAM community Open Access Management (OpenAM) | all versions prior to 16.1.1 (< 16.1.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect authorization endpoint does not sufficiently encode user-supplied parameters before FormPostResponse.ftl and checkSession.ftl render them into HTML for the form_post response mode. An unauthenticated attacker can induce a user to open a crafted authorization request and execute script in the OpenAM origin. This issue is fixed in version 16.1.1.
- Weakness
- CWE-79
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.