CVE-2026-105115: Unauthenticated Class Instantiation Vulnerability in OpenIdentityPlatform
Article Content
- •CVE-2026-105115 allows unauthenticated class loading via OpenAM's SOAP interface.
- •The vulnerability affects all OpenAM versions up to 16.1.2, with a patch available in 16.1.3.
- •Organizations should restrict access to the legacy SOAP interface until patched.
OpenAM versions prior to 16.1.3 contain a high-severity vulnerability (CVE-2026-105115) in the legacy JAX-RPC SOAP interface, allowing unauthenticated remote attackers to load arbitrary classes. This vulnerability can lead to server crashes or potential remote code execution, particularly if the attacker can exploit known gadget chains. Organizations using OpenAM with the legacy SOAP interface exposed to untrusted networks are at risk. The flaw was disclosed on October 3, 2026, with a CVSS score of 8.8, indicating a high priority for remediation. A patch is available in OpenAM version 16.1.3, and operators are advised to apply it promptly. Until then, restricting access to the vulnerable interface is recommended. Current data does not confirm active exploitation, but the potential for serious impact exists.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-105115 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of OpenAM are affected?
What should organizations do to mitigate this risk?
Is there evidence of exploitation in the wild?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…