Authentication Bypass in pac4j-oidc by Pac4j
CVE-2026-82462
6.9MEDIUM
What is CVE-2026-82462?
The vulnerability in pac4j-oidc prior to version 6.5.6 allows malicious actors to exploit weaknesses in the callback handling of OIDC authentication. By sending OIDC callbacks that contain only an access token without proper validation of the authorization code or ID token, attackers can impersonate legitimate users, bypassing issuer, audience, nonce, and subject checks. This flaw presents a significant risk, enabling unauthorized access to protected resources.
Affected Version(s)
pac4j 0 < 6.5.6
