๐Ÿ” CVE Alert

CVE-2026-44793

UNKNOWN 0.0

OpenAM: Pre-authentication Reflected XSS in SAML2 Cluster Cookie-Hash-Redirect Path via `FSUtils.postToTarget`

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non-default clustered configuration inconsistently encode user-supplied parameters rendered into HTML in the SAML2 cluster cookie-hash redirect path. An unauthenticated attacker can induce a user to follow a crafted request and execute script in the OpenAM origin. This issue is fixed in version 16.1.1.

CWE CWE-79
Vendor openidentityplatform
Product openam
Published Sep 15, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for openidentityplatform openam

Be the first to know when new unknown vulnerabilities affecting openidentityplatform openam are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OpenIdentityPlatform / OpenAM
< 16.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-fhrq-3gmx-p879 github.com: https://github.com/OpenIdentityPlatform/OpenAM/commit/2f5e9bf4c28a4c9e97ded6ebd75e4e1ec241c894 github.com: https://github.com/OpenIdentityPlatform/OpenAM/releases/tag/16.1.1