Impact
The vulnerability in pac4j-core before version 6.5.6 is caused by the CheckProfileTypeAuthorizer reversing the profile type validation logic. An attacker can authenticate with a weaker client profile that satisfies generic checks but bypasses the required stronger profile type checks, effectively granting access to resources that should be protected by stricter authorization.
Affected Systems
Pac4j pac4j library, versions below 6.5.6. The affected component is the CheckProfileTypeAuthorizer in pac4j-core.
Risk and Exploitability
The CVSS score of 8.6 classifies this as a high‑severity vulnerability. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves the authentication flow where CheckProfileTypeAuthorizer is invoked, allowing an attacker to impersonate a client with a weaker profile and gain access to resources intended for a stronger profile.
OpenCVE Enrichment