Sceawere
Vulnerability Detail
CVE-2026-105115UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
OpenAM Unauthenticated Arbitrary Class Instantiation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.6
- Creation Date
- 2h ago
- Vendor
- OpenIdentityPlatform
- Product
- OpenAM
- Attack Type
- Missing Authentication for Critical Function
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadget chains.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.6",
"pubDate": "2026-10-03T14:16:38.110Z",
"pubdate": "2026-10-03T14:16:38.110Z",
"executiveSummary": "OpenAM versions prior to 16.1.3 contain a critical vulnerability in the legacy JAX-RPC SOAP interface, specifically involving unauthenticated arbitrary class instantiation. This flaw allows remote, unauthenticated attackers to manipulate the instantiation process of Java classes within the application runtime.\nThe vulnerability exposes the system to several security risks, ranging from service disruption due to application crashes to potential Remote Code Execution (RCE) if specific gadget chains are present within the application's classpath. By sending specially crafted SOAP requests to the /jaxrpc/* endpoint, an attacker can force the server to load arbitrary classes, effectively probing the internal classpath structure or triggering malicious deserialization patterns.\nThis vulnerability is classified as high-risk because it requires no prior authentication, allowing any remote network participant with access to the OpenAM SOAP interface to initiate the exploit. Organizations utilizing affected versions are at significant risk of system instability and unauthorized code execution. The primary mitigation is to upgrade to version 16.1.3 or later, which addresses the underlying flaw in the JAX-RPC endpoint.",
"technicalDetails": "The vulnerability resides in the legacy JAX-RPC (Java API for XML-based RPC) implementation within OpenAM. JAX-RPC is a framework designed for executing remote procedure calls over SOAP. In the affected versions, the framework fails to properly validate the class names provided in the SOAP request parameters before attempting to instantiate them within the JVM.\nThe attack flow begins with the attacker constructing a malicious SOAP request targeted at the /jaxrpc/* endpoint. Because the endpoint does not enforce authentication, the request is processed by the JAX-RPC handler immediately. The request contains an unverified session identifier and a target class identifier. When the framework processes the incoming message, it uses the provided class name to perform a reflection-based instantiation.\nThe root cause is an insecure implementation of object deserialization/instantiation logic that lacks a strict allowlist or sandbox for permitted classes. By supplying an arbitrary class name, the attacker can force the application to load any class currently available on the classpath. This behavior leads to several post-exploitation impacts: first, the attacker can cause a denial-of-service (DoS) condition by triggering constructors that lead to null pointer exceptions or thread exhaustion, resulting in a server crash. Second, the attacker can perform reconnaissance on the application's internal structure by observing responses to identify which classes are present and loadable.\nThe most severe impact involves the potential for Remote Code Execution. If the classpath contains known gadget chains—libraries that perform dangerous operations (like file system writes, process execution, or JNDI lookups) during class instantiation or subsequent method invocation—an attacker can chain these gadgets together through the SOAP payload. By supplying a sequence of objects that conform to the JAX-RPC protocol, the attacker can manipulate the application's state to achieve arbitrary code execution under the privileges of the OpenAM service account. This bypasses typical access controls because the logic flaw exists before the session validation layer of the authentication provider."
}