pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger profile type by satisfying generic profile checks.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 29 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger profile type by satisfying generic profile checks. | |
| Title | pac4j-core before 6.5.6 Authorization Bypass via Reversed Profile Type Check | |
| First Time appeared |
Pac4j
Pac4j pac4j |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pac4j
Pac4j pac4j |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-29T16:35:26.904Z
Reserved: 2026-08-29T14:11:00.955Z
Link: CVE-2026-82463
No data.
Status : Received
Published: 2026-08-29T17:17:58.490
Modified: 2026-08-29T17:17:58.490
Link: CVE-2026-82463
No data.
OpenCVE Enrichment
Updated: 2026-08-29T18:30:13Z
Weaknesses