pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validation. Attackers can substitute access tokens minted for other clients to create authenticated sessions without proper issuer, audience, nonce, or subject verification.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 29 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validation. Attackers can substitute access tokens minted for other clients to create authenticated sessions without proper issuer, audience, nonce, or subject verification. | |
| Title | pac4j-oidc before 6.5.6 Authentication Bypass via Access Token Substitution | |
| First Time appeared |
Pac4j
Pac4j pac4j |
|
| Weaknesses | CWE-345 | |
| CPEs | cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pac4j
Pac4j pac4j |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-29T16:35:26.177Z
Reserved: 2026-08-29T14:11:00.606Z
Link: CVE-2026-82462
No data.
Status : Received
Published: 2026-08-29T17:17:58.350
Modified: 2026-08-29T17:17:58.350
Link: CVE-2026-82462
No data.
OpenCVE Enrichment
Updated: 2026-08-29T17:30:12Z
Weaknesses