CVE-2026-82462
Last modified
CVE-2026-82462 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validation. Attackers can substitute access tokens minted for other clients to create authenticated sessions without proper issuer, audience, nonce, or subject verification.. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validation. Attackers can substitute access tokens minted for other clients to create authenticated sessions without proper issuer, audience, nonce, or subject verification.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| pac4j | pac4j | < 6.5.6 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-82462?
How severe is CVE-2026-82462?
How do I fix CVE-2026-82462?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-82454The Omnivore API (packages/api) before the fix in commit abf…9.1
- CVE-2026-82455RubyGems fails to re-validate path containment after filesys…7.1
- CVE-2026-82456argocd-mcp 0.8.0 binds its HTTP transport to every network i…10
- CVE-2026-82457su-exec through 0.3 fails to validate numeric user and group…7.8
- CVE-2026-82460Cloud Commander before 19.20.2 contains a directory traversa…9.8
- CVE-2026-82461pac4j-oidc before 6.5.6 fails to verify access token signatu…8.1
- CVE-2026-82463pac4j-core before 6.5.6 contains an authentication bypass vu…8.1
- CVE-2026-82464pac4j-core before 6.5.6 contains an open redirect vulnerabil…6.1
- CVE-2026-82465pac4j-saml before 6.5.6 does not require signature validatio…5.3
- CVE-2026-82466Rodauth before 2.46.0 contains an authentication bypass vuln…8.7
- CVE-2026-82467Rodauth before 2.47.0 fails to validate protocol-relative re…4.7
- CVE-2026-82468Rodauth before 2.47.0 contains a cross-site request forgery …4.7
Are you affected by CVE-2026-82462?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
