Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 29 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validation. Attackers can substitute access tokens minted for other clients to create authenticated sessions without proper issuer, audience, nonce, or subject verification. | |
| Title | pac4j-oidc before 6.5.6 Authentication Bypass via Access Token Substitution | |
| First Time appeared |
Pac4j
Pac4j pac4j |
|
| Weaknesses | CWE-345 | |
| CPEs | cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pac4j
Pac4j pac4j |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-29T16:35:26.177Z
Reserved: 2026-08-29T14:11:00.606Z
Link: CVE-2026-82462
No data.
Status : Received
Published: 2026-08-29T17:17:58.350
Modified: 2026-08-29T17:17:58.350
Link: CVE-2026-82462
No data.
OpenCVE Enrichment
Updated: 2026-08-29T17:30:12Z