← Terug naar overzicht

pac4j-core versions before 6.5.6 contain a critical authentication bypass vulnerability in the CheckProfileTypeAuthorizer component. The flaw stems from reversed profile type validation logic, allowing attackers to authenticate using a weaker client and gain access to resources that require a stronger profile type. By satisfying generic profile checks, malicious actors can bypass intended access controls. The vulnerability has been patched in version 6.5.6. A security advisory has been published by the pac4j project, and a fix commit is available on GitHub. This issue affects any application relying on pac4j-core's CheckProfileTypeAuthorizer for enforcing profile-based authorization. Users are strongly advised to upgrade to version 6.5.6 or later to mitigate the risk.

Affected products

  • pac4j-core (before 6.5.6)

Related CVE's

  • CVE-2026-82463

Categories

  • Enterprise Applications
  • Identity & Access
  • Web Technologies