Description
pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validation. Attackers can substitute access tokens minted for other clients to create authenticated sessions without proper issuer, audience, nonce, or subject verification.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sat, 29 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validation. Attackers can substitute access tokens minted for other clients to create authenticated sessions without proper issuer, audience, nonce, or subject verification. | |
| Title | pac4j-oidc before 6.5.6 Authentication Bypass via Access Token Substitution | |
| First Time appeared |
Pac4j
Pac4j pac4j |
|
| Weaknesses | CWE-345 | |
| CPEs | cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pac4j
Pac4j pac4j |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-29T16:35:26.177Z
Reserved: 2026-08-29T14:11:00.606Z
Link: CVE-2026-82462
No data.
Status : Received
Published: 2026-08-29T17:17:58.350
Modified: 2026-08-29T17:17:58.350
Link: CVE-2026-82462
No data.
OpenCVE Enrichment
Updated: 2026-08-29T17:30:12Z
Weaknesses
-
CWE-345
Insufficient Verification of Data Authenticity