Summary
CVE-2026-105115 is a missing authentication vulnerability in OpenAM’s legacy JAX-RPC SOAP interface (/jaxrpc/*) that allows an unauthenticated, network-based attacker to load and instantiate arbitrary Java classes available on the server’s classpath. The flaw affects all OpenAM versions through 16.1.2 and carries a High/Critical severity rating given its unauthenticated, network-exploitable nature and potential for server crashes, classpath enumeration, or code execution.
Technical details
- Root cause: the legacy JAX-RPC SOAP endpoint takes a Java class name directly from the incoming request and loads/instantiates it before verifying that it is of the expected type (CWE-470, Unsafe Reflection with External Input).
- Compounding issue: the operation performs inadequate session validation, accepting session identifiers without actually verifying them (CWE-306, Missing Authentication for Critical Function).
- Trigger conditions: an attacker sends a crafted SOAP request to an exposed
/jaxrpc/*endpoint, supplying an arbitrary class name and an unverified session identifier — no authentication or prior access is required. - Attack vector: network-based, no privileges or user interaction needed.
- Impact: confirmed impacts include denial of service (server crashes) and classpath/class enumeration; the advisory states the theoretical ceiling is remote code execution via gadget chains, though RCE has not been publicly demonstrated.
Affected software
- OpenIdentityPlatform OpenAM versions ≤ 16.1.2 (all versions prior to 16.1.3)
Severity
- CVSS v3.1 Base Score: 8.6 (High) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H - A CVSS v4.0 score of 8.8 (High) has also been published for this CVE.
Mitigation and recommended actions
- Immediate: Upgrade to OpenAM 16.1.3 or later, which contains the fix for this issue.
- If immediate patching is not possible: Restrict network access to the
/jaxrpc/*path at the firewall or reverse-proxy level; if legacy remote SDK clients that depend on the JAX-RPC interface are not in use, block access to this path entirely.

