Sceawere
Vulnerability Detail
CVE-2026-105119UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
OpenAM PKCE Enforcement Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 2h ago
- Vendor
- OpenIdentityPlatform
- Product
- OpenAM
- Attack Type
- Improper Authorization
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued through OpenID Connect hybrid flows (code token, code id_token, code token id_token) carry no bound challenge. An attacker who intercepts such a code can redeem it for a public client's tokens with any non-empty code_verifier.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-10-03T14:16:38.710Z",
"pubdate": "2026-10-03T14:16:38.710Z",
"executiveSummary": "A security vulnerability has been identified in OpenAM versions prior to 16.1.3 within its OAuth2 Provider Proof Key for Code Exchange (PKCE) validation engine. PKCE is a critical security extension designed to mitigate authorization code interception attacks, especially on public clients, by ensuring that only the entity that requested the code can redeem it. However, OpenAM's enforcement mechanism contains a logic flaw: it only applies PKCE validation to authorization requests where the response_type parameter is exactly 'code'. This restrictive check completely bypasses authorization codes generated during OpenID Connect (OIDC) hybrid flows.\nAs a result of this flaw, hybrid flows—such as 'code token', 'code id_token', and 'code token id_token'—do not bind the cryptographic PKCE challenge to the issued authorization code. If an attacker intercepts one of these hybrid authorization codes, they can easily exchange it for valid tokens at the token endpoint using any arbitrary, non-empty 'code_verifier'. This bypass effectively neutralizes PKCE's protections, exposing public clients utilizing hybrid flows to unauthorized session access, credential theft, and complete token compromise without requiring the attacker to possess the legitimate client secrets.",
"technicalDetails": "The root cause of this vulnerability lies in the conditional routing and validation logic within the OpenAM OAuth2 Provider. Under standard RFC 7636 specifications, when a client includes a 'code_challenge' in an authorization request that yields an authorization code, the server must persist this challenge and enforce its verification when the authorization code is redeemed at the token endpoint. However, in vulnerable versions of OpenAM, the system's PKCE enforcement check evaluates whether the 'response_type' parameter of the incoming authorization request strictly matches the literal string 'code'.\nWhen a client initiates an OpenID Connect (OIDC) hybrid flow, the 'response_type' parameter contains multi-valued strings such as 'code token', 'code id_token', or 'code token id_token'. Because these strings do not match the expected singular 'code' value, OpenAM's authorization processing logic skips the binding of the client-provided 'code_challenge' and 'code_challenge_method' to the generated authorization code. Consequently, the issued authorization code is registered in the server's session store without any cryptographic binding or challenge requirements.\nThis behavior exposes a severe vulnerability during the token redemption phase. The attack flow is executed as follows: First, a legitimate user triggers an OIDC hybrid flow request, which includes a valid PKCE 'code_challenge'. Second, OpenAM processes the request but fails to associate the challenge with the resulting authorization code due to the response_type parsing flaw. Third, the authorization code is transmitted back to the client via the user-agent, where an attacker intercepts it. Interception can be achieved through local log exposure, browser history, referrer headers, or network-level sniffing on insecure channels.\nFourth, the attacker, now in possession of the unbound authorization code, issues a POST request to the OpenAM token endpoint to exchange the code for access, ID, and refresh tokens. Fifth, because the database entry for the intercepted authorization code contains no associated PKCE challenge, the verification module reverts to a default validation state where any non-empty string provided in the 'code_verifier' parameter satisfies the check. Finally, the attacker supplies an arbitrary non-empty string as the 'code_verifier' and OpenAM successfully issues the requested public client tokens to the unauthorized actor, granting them full access to the victim's session resources."
}