Sceawere

Vulnerability Detail

CVE-2026-105117UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenAM Email Content Injection Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
2h ago
Vendor
OpenIdentityPlatform
Product
OpenAM
Attack Type
Improper Input Validation
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on /json/{realm}/users. Attackers can supply subject and message fields to send phishing mail from the organisation's configured From address, or abuse register as a relay to arbitrary recipients.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-10-03T14:16:38.413Z",
  "pubdate": "2026-10-03T14:16:38.413Z",
  "executiveSummary": "OpenAM versions prior to 16.1.3 are susceptible to an email content injection vulnerability located within the user management notification workflow. The vulnerability permits unauthenticated actors to manipulate notification email parameters, specifically the subject and body content, when interacting with the 'forgotPassword' and 'register' actions located at /json/{realm}/users. This flaw stems from improper input validation during the construction of notification messages, allowing the injection of arbitrary text into communications dispatched from the organization's verified email address. The primary impact involves the ability to conduct sophisticated phishing campaigns or facilitate email relay abuse, where an attacker can leverage the trusted identity of the organization to reach arbitrary recipients. Because this vulnerability is accessible without authentication, the risk level is high, as it provides an external attacker with a platform to bypass email security filters by using legitimate organizational infrastructure for malicious correspondence.",
  "technicalDetails": "The vulnerability resides within the user notification subsystem of the OpenAM platform, specifically affecting the handlers responsible for the '/json/{realm}/users' endpoint. The flaw exists due to a lack of server-side sanitization and restrictive parameter mapping when processing incoming requests for 'forgotPassword' and 'register' actions. When these specific endpoints are invoked, the application logic fails to validate the 'subject' and 'message' fields against an allowed-list or template-bound configuration, effectively allowing user-supplied input to dictate the content of the generated email.\nExploitation is achieved through the submission of specially crafted JSON payloads to the aforementioned endpoints. An unauthenticated attacker can send an HTTP POST request containing malicious strings within the email metadata fields. Because the OpenAM server automatically utilizes the organization's configured SMTP settings to dispatch these notifications, the injected content is delivered to the recipient with the full credibility of the organization's internal mail server. In the context of the 'register' action, the attacker can specify arbitrary recipient addresses in the target parameters, effectively turning the OpenAM instance into an open mail relay. The server processes the request by populating the email template with the attacker-provided payload, bypassing any intent for static, predefined notification text.\nThe attack flow follows a structured path: first, the attacker identifies a target OpenAM instance and constructs a request targeting the user registration or password reset API. Second, the attacker embeds the phishing content within the JSON payload, targeting either an unsuspecting victim or a third-party address for mass relay. Third, the OpenAM server accepts the malicious input, instantiates the email object, and dispatches the notification via the configured SMTP server. The impact is significant, as it enables high-fidelity social engineering by abusing trusted infrastructure. The lack of authentication requirements at these endpoints facilitates automated, large-scale exploitation, where attackers can distribute phishing lures that appear to originate from legitimate corporate communication channels, potentially resulting in credential theft or the delivery of malicious payloads to internal and external stakeholders."
}