CVE-2026-44793LOWCVSS 0.0

OpenAM SAML2 Cluster Cookie-Hash-Redirect Path has Pre-authentication Reflected XSS via `FSUtils.postToTarget`

Published Jun 22, 2026·Updated Jun 22, 2026

Description

## Summary Certain federation endpoints do not consistently apply output encoding when rendering user-supplied parameters into HTML responses. Under a non-default configuration used in some clustered deployments, this inconsistency can result in reflected XSS in the OpenAM origin without authentication.

Affected Packages (1)

org.openidentityplatform.openam:openam-federation-libraryMAVEN
Fixed in 16.1.1

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free