OpenAM vulnerability allows server-side request forgery (CVE-2026-105122)
A newly disclosed security vulnerability in OpenIdentityPlatform OpenAM could allow attackers to make vulnerable authentication servers send requests to internal systems and resources.
Tracked as CVE-2026-105122, the flaw affects OpenAM versions before 16.1.3 and is classified as a server-side request forgery (SSRF) vulnerability. It has been assigned a CVSS 4.0 score of 5.3, making it a medium-severity security issue.
OAuth client configuration exploited
The vulnerability is linked to the handling of the OpenID Connect `jwks_uri` parameter. This parameter is used to identify where JSON Web Key Sets are located for verifying cryptographic signatures.
According to the vulnerability disclosure, an attacker who can register or modify an OAuth 2.0 client can supply a malicious or otherwise unvalidated `jwks_uri`. OpenAM may then be tricked into making requests to resources chosen by the attacker.
This could potentially allow an attacker to probe internal network hosts, access cloud or infrastructure metadata endpoints, or attempt to retrieve local resources that should not normally be accessible externally.
The vulnerability could also be abused to consume request-processing resources, potentially contributing to denial-of-service conditions.
Authentication required
CVE-2026-105122 is not described as an unauthenticated vulnerability. The attacker needs privileges allowing them to register or modify OAuth 2.0 clients, with the CVSS 3.1 assessment assigning a low-privilege requirement.
The CVSS 3.1 score is 5.4, while the newer CVSS 4.0 assessment rates it at 5.3. The vulnerability is classified under CWE-918, which covers server-side request forgery.
There is currently no indication that CVE-2026-105122 has been added to CISA’s Known Exploited Vulnerabilities catalogue, and Rapid7 currently lists no known exploitation in the wild.
OpenAM 16.1.3 fixes the problem
The affected range is OpenAM versions 0 up to, but not including, 16.1.3. OpenAM 16.1.3 is listed as the unaffected version.
Organisations running OpenAM should therefore review their deployments and upgrade to version 16.1.3 or later where possible.
The disclosure is particularly relevant to organisations using OpenAM as part of their identity and access-management infrastructure, as a successful SSRF attack against an authentication platform could provide attackers with a way to interact with systems that would otherwise be inaccessible from the internet.
CVE-2026-105122 was published on 3 October 2026, with the vulnerability disclosure crediting several researchers including arpitjain099, santhreal, alex-sc, jamesbishup, ayhambashtawi2-lang, maximthomas and tsujiguchitky.
**SystemTek security advice:** Organisations running OpenAM should identify affected installations, review OAuth 2.0 client permissions and upgrade to OpenAM 16.1.3 or later. Administrators should also monitor outbound connections from OpenAM servers for unexpected requests to internal addresses or cloud metadata services.

Blogger at www.systemtek.co.uk
