← Terug naar overzicht

CVE-2026-82461 affects pac4j-oidc versions before 6.5.6, which fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. This critical flaw allows attackers to forge access tokens with administrative roles and pair them with valid ID tokens to bypass authorization checks. Applications relying on pac4j role validation for access control are vulnerable to privilege escalation. The vulnerability resides in the KeycloakRolesAuthorizationGenerator class. A fix was introduced in pac4j version 6.5.6 via a specific commit. Organizations using pac4j with Keycloak integration should upgrade immediately to mitigate the risk of unauthorized administrative access.

Affected products

  • Keycloak
  • pac4j
  • pac4j-oidc

Related CVE's

  • CVE-2026-82461

Categories

  • Enterprise Applications
  • Identity & Access
  • Web Technologies