Unauthenticated Arbitrary Class Instantiation in OpenAM
OpenAM versions prior to 16.1.3 are vulnerable to unauthenticated arbitrary class instantiation via the legacy JAX-RPC SOAP interface, enabling potential remote code execution.
CVE search metadata
CVE search record: CVE-2026-105115. Severity: high. CVSS: 8.6. KEV: no. Product: OpenAM (< 16.1.3). Brief: Unauthenticated Arbitrary Class Instantiation in OpenAM. Brief link: https://feed.craftedsignal.io/briefs/2026-10-openam-cve-2026-105115/
ForgeRock OpenAM versions prior to 16.1.3 contain a critical vulnerability in the legacy JAX-RPC SOAP interface that allows for unauthenticated arbitrary class instantiation. The vulnerability exists within the application's processing of SOAP requests, specifically when interacting with the /jaxrpc/* endpoint. An unauthenticated attacker can supply a specially crafted SOAP request containing an unverified session identifier and a targeted class name to trigger class instantiation within the JVM. This behavior can be weaponized to enumerate the application classpath, cause a denial-of-service through server crashes, or achieve remote code execution (RCE) by leveraging gadget chains available in the server's environment. Defenders should prioritize patching OpenAM instances and restricting access to legacy interfaces.
Impact
Successful exploitation of this vulnerability allows unauthenticated remote attackers to achieve remote code execution, perform classpath discovery, or crash the OpenAM service. This poses a significant risk to identity and access management infrastructure, potentially compromising all integrated services protected by the affected OpenAM deployment.
Recommendation
- Patch all ForgeRock OpenAM instances to version 16.1.3 or later immediately to remediate CVE-2026-105115.
- Monitor web server and application logs for POST requests directed at the /jaxrpc/* URI path from untrusted or external IP addresses.
- Restrict network access to the /jaxrpc/* endpoint at the edge firewall or web application firewall (WAF) to only authorized internal management segments.
Immediate actions
Patch all OpenAM instances to 16.1.3 or later
Mitigations
Restrict external network access to /jaxrpc/*
CVE-2026-105115
Detection coverage 1
Detect Potential CVE-2026-105115 Exploitation - Unauthenticated JAX-RPC Access
highDetects unauthenticated SOAP requests to the legacy JAX-RPC endpoint, a known vector for CVE-2026-105115
Detection queries are available on the platform. Get full rules →