CVE-2026-105118 | OpenIdentityPlatform OpenAM up to 16.1.2 Session Endpoint endSession id_token_hint redirect
A vulnerability identified as problematic has been detected in OpenIdentityPlatform OpenAM up to 16.1.2. Affected by this issue is some unknown functionality of the file /oauth2/connect/endSession of the component Session Endpoint. This manipulation of the argument id_token_hint causes open redirect.
The identification of this vulnerability is CVE-2026-105118. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More