HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-105115 — OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation v...
·Source: NIST NVD
Updated:
Executive Summary
OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadge
Analysis
OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. Attackers can send SOAP requests to /jaxrpc/* with an unverified session identifier and a chosen class name, crashing the server, probing the classpath, or potentially reaching code execution via gadget chains. CVSS Score: 8.6. Published: 2026-10-03T14:16:38.110.