{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aforgerockopenam/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:forgerock:openam:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-105115"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenAM (\u003c 16.1.3)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","webserver"],"_cs_type":"advisory","_cs_vendors":["ForgeRock"],"content_html":"\u003cp\u003eForgeRock OpenAM versions prior to 16.1.3 contain a critical vulnerability in the legacy JAX-RPC SOAP interface that allows for unauthenticated arbitrary class instantiation. The vulnerability exists within the application's processing of SOAP requests, specifically when interacting with the /jaxrpc/* endpoint. An unauthenticated attacker can supply a specially crafted SOAP request containing an unverified session identifier and a targeted class name to trigger class instantiation within the JVM. This behavior can be weaponized to enumerate the application classpath, cause a denial-of-service through server crashes, or achieve remote code execution (RCE) by leveraging gadget chains available in the server's environment. Defenders should prioritize patching OpenAM instances and restricting access to legacy interfaces.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated remote attackers to achieve remote code execution, perform classpath discovery, or crash the OpenAM service. This poses a significant risk to identity and access management infrastructure, potentially compromising all integrated services protected by the affected OpenAM deployment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch all ForgeRock OpenAM instances to version 16.1.3 or later immediately to remediate CVE-2026-105115.\u003c/li\u003e\n\u003cli\u003eMonitor web server and application logs for POST requests directed at the /jaxrpc/* URI path from untrusted or external IP addresses.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the /jaxrpc/* endpoint at the edge firewall or web application firewall (WAF) to only authorized internal management segments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-03T14:56:21Z","date_published":"2026-10-03T14:56:21Z","id":"https://feed.craftedsignal.io/briefs/2026-10-openam-cve-2026-105115/","summary":"OpenAM versions prior to 16.1.3 are vulnerable to unauthenticated arbitrary class instantiation via the legacy JAX-RPC SOAP interface, enabling potential remote code execution.","title":"Unauthenticated Arbitrary Class Instantiation in OpenAM","url":"https://feed.craftedsignal.io/briefs/2026-10-openam-cve-2026-105115/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:forgerock:openam:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}