PT-2026-51443 · Maven · Org.Openidentityplatform.Openam:Openam-Federation-Library

Published

2026-06-22

·

Updated

2026-06-22

·

CVE-2026-44793

CVSS v4.0

2.3

Low

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Summary

Certain federation endpoints do not consistently apply output encoding when rendering user-supplied parameters into HTML responses. Under a non-default configuration used in some clustered deployments, this inconsistency can result in reflected XSS in the OpenAM origin without authentication.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44793
GHSA-FHRQ-3GMX-P879

Affected Products

Org.Openidentityplatform.Openam:Openam-Federation-Library