PT-2026-83445 · Unknown · Pac4J-Saml

·

CVE-2026-82465

·

Published

2026-08-29

·

Updated

2026-08-29

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pac4j-saml versions prior to 6.5.6
Description The software fails to require signature validation for SAML LogoutRequest messages within the validateLogoutRequest() function of the SAML2LogoutValidator. If an Identity Provider (IdP) does not send a SessionIndex, the system allows session destruction based only on the NameID. This enables an unauthenticated attacker to terminate a victim's SAML session by submitting an unsigned LogoutRequest using a guessed identifier, such as an email address used as the NameID.
Recommendations Update pac4j-saml to version 6.5.6 or later.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82465

Affected Products

Pac4J-Saml