Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 29 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger profile type by satisfying generic profile checks. | |
| Title | pac4j-core before 6.5.6 Authorization Bypass via Reversed Profile Type Check | |
| First Time appeared |
Pac4j
Pac4j pac4j |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pac4j
Pac4j pac4j |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-02T18:09:56.553Z
Reserved: 2026-08-29T14:11:00.955Z
Link: CVE-2026-82463
Updated: 2026-09-02T18:09:52.551Z
Status : Deferred
Published: 2026-08-29T17:17:58.490
Modified: 2026-09-02T19:18:06.810
Link: CVE-2026-82463
No data.
OpenCVE Enrichment
Updated: 2026-08-29T18:30:13Z