Sceawere
Vulnerability Detail
CVE-2026-105118UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
OpenAM Open Redirect Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.7
- Creation Date
- 2h ago
- Vendor
- OpenIdentityPlatform
- Product
- OpenAM
- Attack Type
- Improper Verification of Cryptographic Signature
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.7",
"pubDate": "2026-10-03T14:16:38.563Z",
"pubdate": "2026-10-03T14:16:38.563Z",
"executiveSummary": "OpenAM versions prior to 16.1.3 are susceptible to an open redirect vulnerability located within the OpenID Connect (OIDC) end-session functionality. This flaw allows an unauthenticated remote attacker to weaponize the /oauth2/connect/endSession endpoint to facilitate phishing campaigns.\nBy supplying a maliciously crafted or unverified id_token_hint, an attacker can manipulate the application's redirect logic, effectively bypassing intended security controls. The vulnerability permits the redirection of unsuspecting users to arbitrary, attacker-controlled domains that masquerade as legitimate services. Since the redirect originates from a trusted host, the attack carries a higher probability of social engineering success. The primary risk involves credential harvesting or malware delivery via phishing, leveraging the implicit trust users place in the primary identity provider's domain. Exploitation does not require prior authentication or elevated privileges, making this an attractive vector for external threat actors seeking to compromise user identities or exfiltrate sensitive session data.",
"technicalDetails": "The vulnerability resides in the OIDC end-session implementation of OpenAM, specifically within the /oauth2/connect/endSession endpoint. The root cause is the improper validation of the id_token_hint parameter during the logout process. When an OpenID Connect provider processes a logout request, it typically validates the identity token to ensure the request is legitimate and to resolve the associated user session and post-logout redirect URI.\nIn the affected versions, the application fails to adequately verify the integrity and claims contained within the id_token_hint provided by the user-agent. An unauthenticated attacker can forge this hint, populating it with arbitrary values that reference any registered realm client within the OpenAM ecosystem. Because the application logic relies on the claims within this unverified hint to determine the redirection target, it effectively trusts the attacker-supplied input without verifying the token's signature, issuer, or expiration status.\nThe attack flow proceeds as follows: First, the attacker identifies a valid realm client registered within the OpenAM instance. Second, the attacker crafts a malicious request targeting /oauth2/connect/endSession, embedding a forged id_token_hint that points to the identified client. Within the metadata for that client, the attacker targets a configured post-logout URI. Because the validation logic is flawed, OpenAM accepts the request and triggers a 302 redirect response to the URL defined by the malicious hint.\nBy chaining this with an open redirect, the attacker directs the victim's browser to an arbitrary URI. If the destination is an attacker-controlled site, the victim is led away from the secure OpenAM environment to a malicious phishing page. Because the user arrives at the external site via a trusted, authentic request from the OpenAM host, traditional domain-based trust indicators are obscured, significantly increasing the risk of successful user credential theft. The vulnerability is highly accessible as it requires no active user session, administrative access, or specific service configuration beyond the existence of a standard OIDC client registration. This flaw highlights a failure to enforce strictly bounded allow-lists for post-logout redirection URIs when the id_token_hint is provided or malformed."
}