CVE-2026-105118
MEDIUM
NVD
CVSS Score
4.7
Severity
MEDIUM
Published
Oct 03, 2026
Vendor
unknown
Description
OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust.