PT-2026-83441 · Unknown · Pac4J-Oidc

·

CVE-2026-82461

·

Published

2026-08-29

·

Updated

2026-08-29

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pac4j-oidc versions prior to 6.5.6
Description The software fails to verify access token signatures, issuers, audiences, or expiry during the extraction of Keycloak realm and client roles. This allows attackers to forge access tokens containing administrative roles and pair them with valid ID tokens to bypass authorization checks in applications that rely on pac4j role validation.
Recommendations Update pac4j-oidc to version 6.5.6 or later.

Exploit

Fix

LPE

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82461

Affected Products

Pac4J-Oidc