๐Ÿ” CVE Alert

CVE-2026-44203

UNKNOWN 0.0

OpenAM: Pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect authorization endpoint does not sufficiently encode user-supplied parameters before FormPostResponse.ftl and checkSession.ftl render them into HTML for the form_post response mode. An unauthenticated attacker can induce a user to open a crafted authorization request and execute script in the OpenAM origin. This issue is fixed in version 16.1.1.

CWE CWE-79
Vendor openidentityplatform
Product openam
Published Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for openidentityplatform openam

Be the first to know when new unknown vulnerabilities affecting openidentityplatform openam are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OpenIdentityPlatform / OpenAM
< 16.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-fq9h-c788-fx73 github.com: https://github.com/OpenIdentityPlatform/OpenAM/commit/078bd4754905f5130eaa7bbe45f958eaeb7fd0d7 github.com: https://github.com/OpenIdentityPlatform/OpenAM/releases/tag/16.1.1