PT-2026-104580 · Forgerock · Openam

·

CVE-2026-105119

·

Published

2026-10-03

·

Updated

2026-10-03

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenAM versions prior to 16.1.3
Description The OAuth2 Provider PKCE enforcement is only applied to authorization requests where the response type is exactly code. Consequently, codes issued via OpenID Connect hybrid flows (such as code token, code id token, or code token id token) are not bound to a challenge. This allows an attacker who intercepts such a code to redeem it for tokens of a public client using any non-empty code verifier. PKCE (Proof Key for Code Exchange) is a security extension used to prevent authorization code injection attacks.
Recommendations Update OpenAM to version 16.1.3 or later.

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105119

Affected Products

Openam