Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non-default clustered configuration inconsistently encode user-supplied parameters rendered into HTML in the SAML2 cluster cookie-hash redirect path. An unauthenticated attacker can induce a user to follow a crafted request and execute script in the OpenAM origin. This issue is fixed in version 16.1.1.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-79"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44793.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "16.1.1"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44793.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"157390719585320742569889059562128316161",
"271424486726578249307539842628883735462",
"88584819781113049020412163710367936280",
"338394690224403035348409550139942064537",
"140765879487334552998392784298541476149",
"246655998913410656867885612595917087347",
"264429196161255648604119645636473482411",
"48520662165398601720825759912008069214",
"290946605164173673182438131699748374104",
"276040575732984725008038861517714677637"
],
"threshold": 0.9
},
"id": "CVE-2026-44793-0cda0664",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openidentityplatform/openam/commit/2f5e9bf4c28a4c9e97ded6ebd75e4e1ec241c894",
"target": {
"file": "openam-oauth2/src/main/java/org/forgerock/oauth2/core/AuthorizeRequestValidatorImpl.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "118249618653741939371780428901379161812",
"length": 977
},
"id": "CVE-2026-44793-f22430df",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openidentityplatform/openam/commit/2f5e9bf4c28a4c9e97ded6ebd75e4e1ec241c894",
"target": {
"file": "openam-oauth2/src/main/java/org/forgerock/oauth2/core/AuthorizeRequestValidatorImpl.java",
"function": "validateRequest"
}
}
]
"2026-09-25T08:21:34Z"