Sceawere
Vulnerability Detail
CVE-2026-105122UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
OpenAM Server-Side Request Forgery
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 2h ago
- Vendor
- OpenIdentityPlatform
- Product
- OpenAM
- Attack Type
- Server-Side Request Forgery (SSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe internal hosts, metadata endpoints or local files, or exhaust request threads for denial of service.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-03T14:16:39.140Z",
"pubdate": "2026-10-03T14:16:39.140Z",
"executiveSummary": "OpenAM versions prior to 16.1.3 are susceptible to a Server-Side Request Forgery (SSRF) vulnerability originating from improper validation of the jwks_uri parameter in OAuth 2.0 client configurations.\nThis vulnerability permits attackers with the ability to register or modify OAuth 2.0 clients to force the OpenAM server to initiate unauthorized outbound HTTP requests to arbitrary internal or external resources.\nThe scope of the impact includes the potential exposure of sensitive internal infrastructure, local metadata endpoints, or local files, as well as the depletion of server request threads, leading to a Denial of Service (DoS) condition.\nExploitation requires the attacker to possess sufficient privileges to configure or update OAuth 2.0 client settings, but once triggered, subsequent requests can be initiated without further authentication, such as during ID-token validation or client-authentication processes.\nThis flaw presents a significant security risk by bypassing network segmentation and security controls typically protecting internal services from public or unauthorized access.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient server-side validation of the jwks_uri (JSON Web Key Set URI) property during the OAuth 2.0 client registration or update workflow. OpenAM relies on the jwks_uri to retrieve public keys required for cryptographic verification of tokens. However, the implementation fails to enforce strict allow-listing or validate the destination of the requested URI, allowing an attacker to inject arbitrary internal or external endpoints.\nWhen an attacker provides a malicious URL for the jwks_uri, OpenAM performs an outbound GET request to the supplied location. Because this request is originated by the server itself, the underlying HTTP client operates within the trust context of the OpenAM host. This allows attackers to bypass perimeter firewalls to scan internal network segments, interact with metadata services (such as cloud instance identity documents), or access local files accessible to the application process if the underlying library supports file:// URI schemes.\nThe attack flow proceeds in three stages. First, the attacker registers a new OAuth 2.0 client or modifies an existing one via the administrative API, setting the jwks_uri to a targeted resource (e.g., http://internal-service:8080 or file:///etc/passwd). Second, the attacker initiates a process that triggers the use of this client, such as an authentication request or ID-token validation flow. Third, the OpenAM server retrieves the value of the jwks_uri and executes an HTTP request to the attacker-supplied destination. The server processes the response, potentially returning error messages that leak information about the target service, or simply exhausting system resources if the attacker points the URI to a service that induces high latency or large responses.\nThe vulnerability is primarily exploitable through the OAuth 2.0 client configuration interface, requiring the attacker to have permissions sufficient to manage these configurations. The issue is persistent across all deployments of OpenAM before 16.1.3. Impact extends beyond mere SSRF; the ability to cause the server to repeatedly perform these requests can be leveraged as an effective DoS vector, tying up server request threads and degrading the performance of the identity provider infrastructure, eventually leading to a complete service outage."
}