Authentication Bypass Vulnerability in pac4j-core by pac4j
CVE-2026-82463
8.6HIGH
What is CVE-2026-82463?
The pac4j-core library prior to version 6.5.6 has an authentication bypass vulnerability stemming from a flaw in the CheckProfileTypeAuthorizer. This flaw allows attackers to authenticate as a weaker client and subsequently gain access to resources which ideally require a stronger profile type. The vulnerability compromises the intended profile validation mechanism, enabling unauthorized access to sensitive resources by only meeting general profile checks.
Affected Version(s)
pac4j 0 < 6.5.6
