CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105118

MEDIUMCVSS 4.7NVD feed

Published 3 October 2026 · tracked since 3 October 2026

Description

OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-lo

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-105118 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105118

MEDIUMCVSS 4.7NVD feed

Published 3 October 2026 · tracked since 3 October 2026

Description

OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-lo

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]