CVE-2026-105116

CVE-2026-105116 published: OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-balancer cookie bounce auto-submit page. If reachable with cookieHashRedirectEnabled set, crafted requests co...

View full NVD advisory → ← Back to CVE watch