CVE-2026-82463: PAC4J

High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.

pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger profile type by satisfying generic profile checks.

Affected products

  • PAC4J PAC4J: before 6.5.6 (fixed in 6.5.6)

Published 2026-08-29. Last modified 2026-09-02.