ZeroHour

CVE-2026-44793

moderate

Reflected XSS in OpenAM SAML2 Cluster Redirect Paths Before 16.1.1

CVSS 4.0
7.0 high
EPSS
Published
()
Modified
AI analysis

Open Access Management (OpenAM) versions prior to 16.1.1 contain a reflected cross-site scripting flaw (CWE-79) in certain federation endpoints that are active only in a non-default clustered configuration, where user-supplied parameters are inconsistently HTML-encoded in the SAML2 cluster cookie-hash redirect path. An unauthenticated attacker crafts a malicious link or request and induces a victim to follow it, causing attacker-supplied script to execute in the victim's browser under the trusted OpenAM origin. Successful exploitation can yield high integrity impact on the web content of the OpenAM instance and its downstream SSO context — for example, tampering with authentication flows or acting on the victim's authenticated session — though the attack requires user interaction and is limited to deployments with the vulnerable clustered setup. The issue is rated high severity (CVSS 4.0: 7.0) and is fixed in OpenAM 16.1.1. There is no known public proof of concept, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported.

What to do: Upgrade OpenAM to version 16.1.1, which fixes the flaw. If immediate patching is not possible, verify whether you run a clustered configuration with SAML2 federation enabled (the vulnerable path is inactive in default deployments), and restrict or gateway access to the affected federation endpoints. Additionally, inspect web access logs for unsolicited requests to SAML2 redirect endpoints containing HTML/script syntax in parameters, and consider a WAF rule to block script payloads in those redirect parameters until upgraded.

Affected
Open Identity Platform Community (OpenAM) Open Access Management (OpenAM)all versions prior to 16.1.1 (< 16.1.1)
Estimated exposure
moderatelow thousands of internet-exposed OpenAM instances (~1,000-5,000), with the genuinely vulnerable subset (non-default clustered federation setups) likely smaller — OpenAM is a self-hosted, predominantly enterprise SSO product with no public install counts, but internet-wide scans typically fingerprint a few thousand exposed OpenAM servers; only those running the non-default clustered configuration…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non-default clustered configuration inconsistently encode user-supplied parameters rendered into HTML in the SAML2 cluster cookie-hash redirect path. An unauthenticated attacker can induce a user to follow a crafted request and execute script in the OpenAM origin. This issue is fixed in version 16.1.1.

Weakness
CWE-79
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.