<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>ForgeRock - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/forgerock/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 14:56:21 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/forgerock/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Arbitrary Class Instantiation in OpenAM</title><link>https://feed.craftedsignal.io/briefs/2026-10-openam-cve-2026-105115/</link><pubDate>Sat, 03 Oct 2026 14:56:21 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-openam-cve-2026-105115/</guid><description>OpenAM versions prior to 16.1.3 are vulnerable to unauthenticated arbitrary class instantiation via the legacy JAX-RPC SOAP interface, enabling potential remote code execution.</description><content:encoded><![CDATA[<p>ForgeRock OpenAM versions prior to 16.1.3 contain a critical vulnerability in the legacy JAX-RPC SOAP interface that allows for unauthenticated arbitrary class instantiation. The vulnerability exists within the application's processing of SOAP requests, specifically when interacting with the /jaxrpc/* endpoint. An unauthenticated attacker can supply a specially crafted SOAP request containing an unverified session identifier and a targeted class name to trigger class instantiation within the JVM. This behavior can be weaponized to enumerate the application classpath, cause a denial-of-service through server crashes, or achieve remote code execution (RCE) by leveraging gadget chains available in the server's environment. Defenders should prioritize patching OpenAM instances and restricting access to legacy interfaces.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthenticated remote attackers to achieve remote code execution, perform classpath discovery, or crash the OpenAM service. This poses a significant risk to identity and access management infrastructure, potentially compromising all integrated services protected by the affected OpenAM deployment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch all ForgeRock OpenAM instances to version 16.1.3 or later immediately to remediate CVE-2026-105115.</li>
<li>Monitor web server and application logs for POST requests directed at the /jaxrpc/* URI path from untrusted or external IP addresses.</li>
<li>Restrict network access to the /jaxrpc/* endpoint at the edge firewall or web application firewall (WAF) to only authorized internal management segments.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>rce</category><category>webserver</category></item></channel></rss>