PT-2026-83442 · Unknown · Pac4J-Oidc

·

CVE-2026-82462

·

Published

2026-08-29

·

Updated

2026-08-29

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pac4j-oidc versions prior to 6.5.6
Description The software accepts OpenID Connect (OIDC) callbacks that contain only an access token, bypassing the required authorization code or ID token validation. This allows attackers to use access tokens intended for different clients to establish authenticated sessions because the system fails to verify the issuer, audience, nonce, or subject.
Recommendations Update pac4j-oidc to version 6.5.6 or later.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82462

Affected Products

Pac4J-Oidc