Skip to content
Threat Feed
high advisory

Unauthenticated Arbitrary Class Instantiation in OpenAM

OpenAM versions prior to 16.1.3 are vulnerable to unauthenticated arbitrary class instantiation via the legacy JAX-RPC SOAP interface, enabling potential remote code execution.

CVE search metadata

CVE search record: CVE-2026-105115. Severity: high. CVSS: 8.6. KEV: no. Product: OpenAM (< 16.1.3). Brief: Unauthenticated Arbitrary Class Instantiation in OpenAM. Brief link: https://feed.craftedsignal.io/briefs/2026-10-openam-cve-2026-105115/

ForgeRock OpenAM versions prior to 16.1.3 contain a critical vulnerability in the legacy JAX-RPC SOAP interface that allows for unauthenticated arbitrary class instantiation. The vulnerability exists within the application's processing of SOAP requests, specifically when interacting with the /jaxrpc/* endpoint. An unauthenticated attacker can supply a specially crafted SOAP request containing an unverified session identifier and a targeted class name to trigger class instantiation within the JVM. This behavior can be weaponized to enumerate the application classpath, cause a denial-of-service through server crashes, or achieve remote code execution (RCE) by leveraging gadget chains available in the server's environment. Defenders should prioritize patching OpenAM instances and restricting access to legacy interfaces.

Impact

Successful exploitation of this vulnerability allows unauthenticated remote attackers to achieve remote code execution, perform classpath discovery, or crash the OpenAM service. This poses a significant risk to identity and access management infrastructure, potentially compromising all integrated services protected by the affected OpenAM deployment.

Recommendation

  • Patch all ForgeRock OpenAM instances to version 16.1.3 or later immediately to remediate CVE-2026-105115.
  • Monitor web server and application logs for POST requests directed at the /jaxrpc/* URI path from untrusted or external IP addresses.
  • Restrict network access to the /jaxrpc/* endpoint at the edge firewall or web application firewall (WAF) to only authorized internal management segments.

Immediate actions

Patch all OpenAM instances to 16.1.3 or later

IT Operations 48h

Mitigations

Restrict external network access to /jaxrpc/*

immediate Network Security

CVE-2026-105115

Detection coverage 1

Detect Potential CVE-2026-105115 Exploitation - Unauthenticated JAX-RPC Access

high

Detects unauthenticated SOAP requests to the legacy JAX-RPC endpoint, a known vector for CVE-2026-105115

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →