Vulnerability Description
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect authorization endpoint does not sufficiently encode user-supplied parameters before FormPostResponse.ftl and checkSession.ftl render them into HTML for the form_post response mode. An unauthenticated attacker can induce a user to open a crafted authorization request and execute script in the OpenAM origin. This issue is fixed in version 16.1.1.
Related Weaknesses (CWE)
References
- https://github.com/OpenIdentityPlatform/OpenAM/commit/078bd4754905f5130eaa7bbe45
- https://github.com/OpenIdentityPlatform/OpenAM/releases/tag/16.1.1
- https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-fq9h-c78
FAQ
What is CVE-2026-44203?
CVE-2026-44203 is a documented vulnerability. Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect authorization endpoint does not sufficiently encode user-supplied parameters before ...
How severe is CVE-2026-44203?
CVSS scoring is not yet available for CVE-2026-44203. Check NVD for updates.
Is there a patch for CVE-2026-44203?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.