← Back to the live CVE advisory feed

CVE-2026-105118: OpenAM

Severity
2.3 (LOW)
Vendor
OPENAM BEFORE
Affected versions
0 through before 16.1.3
Fixed version
16.1.3
Patch status
Patched
Published
2026-10-03T14:16:38.563
Modified
2026-10-03T14:16:38.563

Why it matters

This matters because the issue affects identity or token handling. Successful exploitation could allow unauthorized authentication, client manipulation, or access to protected services.

Recommended admin actions

  • Review during normal vulnerability triage unless the affected system is internet-facing or business-critical.
  • Compare installed versions against the affected version range in the advisory.
  • Treat internet-facing systems as higher priority.

Technical summary

OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: OCT 04, 2026 08:00 AM UTC
54 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-105105
AIT-Core PATCH
Reporter: 309F9EA4-E3E9-4C6C-B79D-E8EB01244F2C
9.8
CRITICAL
VIEW RECORD
CVE-2026-105134
AhsayCBS PATCH
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-105135
MindSearch
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-71885
BC-JAVA PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
9.2
CRITICAL
VIEW RECORD
CVE-2026-92084
Beaver Builder Page Builder – Drag and Drop Website Builder
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-105115
OpenAM PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-96451
Ultimate Member PATCH
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-71888
BC-JAVA PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.7
HIGH
VIEW RECORD
CVE-2026-71889
BC-JAVA PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.7
HIGH
VIEW RECORD
CVE-2026-71890
BC-JAVA PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.7
HIGH
VIEW RECORD
CVE-2026-105123
wcms
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-88779
ADC PATCH
Reporter: 50A63C94-1EA7-4568-8C11-EB79E7C5A2B5
8.7
HIGH
VIEW RECORD
CVE-2026-105126
laradashboard PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-71883
BC-LTS-JAVA PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.2
HIGH
VIEW RECORD
CVE-2026-71886
BC-JAVA PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.2
HIGH
VIEW RECORD
CVE-2026-71887
BC-JAVA PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.2
HIGH
VIEW RECORD
CVE-2026-85515
BC-JAVA PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
8.2
HIGH
VIEW RECORD
CVE-2026-103065
Kirki PATCH
Reporter: AUDIT
8.2
HIGH
VIEW RECORD
CVE-2026-105119
OpenAM PATCH
Reporter: DISCLOSURE
7.6
HIGH
VIEW RECORD
CVE-2026-71891
BC-JAVA PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
7.1
HIGH
VIEW RECORD
CVE-2026-105113
nezha PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-103342
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) PATCH
Reporter: AUDIT
7.1
HIGH
VIEW RECORD
CVE-2026-105129
laradashboard PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-71892
BC-JAVA PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
6.9
MEDIUM
VIEW RECORD
CVE-2026-105120
OpenAM PATCH
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-105121
OpenAM PATCH
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-105127
laradashboard PATCH
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-92767
Twenty20 Image Before-After
Reporter: SECURITY
6.4
MEDIUM
VIEW RECORD
CVE-2026-105125
laradashboard PATCH
Reporter: DISCLOSURE
6.3
MEDIUM
VIEW RECORD
CVE-2026-105130
laradashboard PATCH
Reporter: DISCLOSURE
6.3
MEDIUM
VIEW RECORD
CVE-2026-105112
nezha PATCH
Reporter: DISCLOSURE
6
MEDIUM
VIEW RECORD
CVE-2026-18040
BC-JAVA PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
5.9
MEDIUM
VIEW RECORD
CVE-2026-105133
AhsayCBS PATCH
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-97873
BC-JAVA PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
5.3
MEDIUM
VIEW RECORD
CVE-2026-105114
OpenAM PATCH
Reporter: DISCLOSURE
5.3
MEDIUM
VIEW RECORD
CVE-2026-105117
OpenAM PATCH
Reporter: DISCLOSURE
5.3
MEDIUM
VIEW RECORD
CVE-2026-105122
OpenAM PATCH
Reporter: DISCLOSURE
5.3
MEDIUM
VIEW RECORD
CVE-2026-105124
wcms
Reporter: DISCLOSURE
5.3
MEDIUM
VIEW RECORD
CVE-2026-105128
laradashboard PATCH
Reporter: DISCLOSURE
5.3
MEDIUM
VIEW RECORD
CVE-2026-105131
ezBookkeeping PATCH
Reporter: DISCLOSURE
5.3
MEDIUM
VIEW RECORD
CVE-2026-105116
OpenAM PATCH
Reporter: DISCLOSURE
5.1
MEDIUM
VIEW RECORD
CVE-2026-105118
OpenAM PATCH
Reporter: DISCLOSURE
2.3
LOW
VIEW RECORD
CVE-2026-104982
Xreader PATCH
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-104983
Xreader
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-105096
CoinEx Crypto
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-105097
CoinEx Crypto
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-105098
CoinEx Crypto
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-105099
CoinEx Crypto
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-104118
Razorpay for WooCommerce PATCH
Reporter: CONTACT
0
N/A
VIEW RECORD
CVE-2026-104119
Simple Shopping Cart PATCH
Reporter: CONTACT
0
N/A
VIEW RECORD
CVE-2026-17005
Horizontal scrolling announcements
Reporter: CONTACT
0
N/A
VIEW RECORD
CVE-2026-86817
Five Star Business Profile and Schema PATCH
Reporter: CONTACT
0
N/A
VIEW RECORD
CVE-2026-93549
CoCart PATCH
Reporter: CONTACT
0
N/A
VIEW RECORD
CVE-2026-97332
User Private Files PATCH
Reporter: CONTACT
0
N/A
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.