Skip to content
CVE-2026-105115: Unauthenticated Class Instantiation Vulnerability in OpenIdentityPlatform

CVE-2026-105115: Unauthenticated Class Instantiation Vulnerability in OpenIdentityPlatform

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC
  • •CVE-2026-105115 allows unauthenticated class loading via OpenAM's SOAP interface.
  • •The vulnerability affects all OpenAM versions up to 16.1.2, with a patch available in 16.1.3.
  • •Organizations should restrict access to the legacy SOAP interface until patched.

OpenAM versions prior to 16.1.3 contain a high-severity vulnerability (CVE-2026-105115) in the legacy JAX-RPC SOAP interface, allowing unauthenticated remote attackers to load arbitrary classes. This vulnerability can lead to server crashes or potential remote code execution, particularly if the attacker can exploit known gadget chains. Organizations using OpenAM with the legacy SOAP interface exposed to untrusted networks are at risk. The flaw was disclosed on October 3, 2026, with a CVSS score of 8.8, indicating a high priority for remediation. A patch is available in OpenAM version 16.1.3, and operators are advised to apply it promptly. Until then, restricting access to the vulnerable interface is recommended. Current data does not confirm active exploitation, but the potential for serious impact exists.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-03
CVE-2026-105115 published
OpenAM disclosed a high-severity vulnerability in its legacy JAX-RPC SOAP interface, affecting versions up to 16.1.2.
Redpacketsecurity
2026-10-03
Advisory issued on vulnerability
GitHub advisory warns of unauthenticated access risks in OpenAM's legacy SOAP interface.
github.com

More articles in this cluster (3)

Following this threat?

Track CVE-2026-105115 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of OpenAM are affected?
All OpenAM versions prior to 16.1.3 are affected by CVE-2026-105115.
What should organizations do to mitigate this risk?
Organizations should apply the patch in OpenAM 16.1.3 and restrict access to the legacy SOAP interface until then.
Is there evidence of exploitation in the wild?
Current data does not confirm any active exploitation of this vulnerability.