Forgerock · Openam · CVE-2026-105114
**Name of the Vulnerable Software and Affected Versions**
OpenAM versions prior to 16.1.3
**Description**
An issue exists where unauthenticated attackers can perform reflected cross-site scripting (XSS) by providing crafted parameters that are rendered without proper encoding on the OAuth2 authorization error page. By luring victims to a malicious `/oauth2/authorize` endpoint, attackers can execute JavaScript within the OpenAM origin to operate within existing sessions or redirect users to phishing pages.
**Recommendations**
Update to version 16.1.3 or later.