Authentication Bypass in pac4j-oidc by Pac4j
CVE-2026-82462

6.9MEDIUM

Key Information:

Vendor

Pac4j

Status
Vendor
CVE Published:
29 August 2026

What is CVE-2026-82462?

The vulnerability in pac4j-oidc prior to version 6.5.6 allows malicious actors to exploit weaknesses in the callback handling of OIDC authentication. By sending OIDC callbacks that contain only an access token without proper validation of the authorization code or ID token, attackers can impersonate legitimate users, bypassing issuer, audience, nonce, and subject checks. This flaw presents a significant risk, enabling unauthorized access to protected resources.

Affected Version(s)

pac4j 0 < 6.5.6

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joshua Rogers (AISLE Research)
.