HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-105115 — OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation v...

·Source: NIST NVD

Updated:

Executive Summary

OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadge

Analysis

OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadget chains. CVSS Score: 8.6. Published: 2026-10-03T14:16:38.110.

Indicators of Compromise (1)

CVE (1)
CVE-2026-105115
Source Attribution

Originally published by NIST NVD on Oct 3, 2026. Verified by: NIST.

Related Threats