๐Ÿ” CVE Alert

CVE-2026-105115

HIGH 8.6

OpenAM before 16.1.3 Unauthenticated Arbitrary Class Instantiation via JAX-RPC Interface

CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th

OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadget chains.

CWE CWE-306
Vendor openidentityplatform
Product openam
Published Oct 3, 2026
Stay Ahead of the Next One

Get instant alerts for openidentityplatform openam

Be the first to know when new high vulnerabilities affecting openidentityplatform openam are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
High

Affected Versions

OpenIdentityPlatform / OpenAM
0 < 16.1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-wxmx-q96f-w4gw vulncheck.com: https://www.vulncheck.com/advisories/openam-before-16.1.3-unauthenticated-arbitrary-class-instantiation-via-jax-rpc-interface

Credits

๐Ÿ” manus-use ๐Ÿ” alex-sc maximthomas tsujiguchitky