Forgerock · Openam · CVE-2026-105116
**Name of the Vulnerable Software and Affected Versions**
OpenAM versions prior to 16.1.3
**Description**
A cross-site scripting defect exists where the SAML message, relay state, and target URL are placed unencoded into the load-balancer cookie bounce auto-submit page. This issue is reachable when `cookieHashRedirectEnabled` is set, potentially allowing script execution in the OpenAM origin. However, an unrelated HTTP 500 failure prevents exploitation in released versions.
**Recommendations**
Update to version 16.1.3 or later.
As a temporary mitigation, ensure the `cookieHashRedirectEnabled` setting is disabled.