PT-2026-83441 · Unknown · Pac4J-Oidc
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
pac4j-oidc versions prior to 6.5.6
Description
The software fails to verify access token signatures, issuers, audiences, or expiry during the extraction of Keycloak realm and client roles. This allows attackers to forge access tokens containing administrative roles and pair them with valid ID tokens to bypass authorization checks in applications that rely on pac4j role validation.
Recommendations
Update pac4j-oidc to version 6.5.6 or later.
Exploit
Fix
LPE
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pac4J-Oidc