pac4j-core versions before 6.5.6 contain a critical authentication bypass vulnerability in the CheckProfileTypeAuthorizer component. The flaw stems from reversed profile type validation logic, allowing attackers to authenticate using a weaker client and gain access to resources that require a stronger profile type. By satisfying generic profile checks, malicious actors can bypass intended access controls. The vulnerability has been patched in version 6.5.6. A security advisory has been published by the pac4j project, and a fix commit is available on GitHub. This issue affects any application relying on pac4j-core's CheckProfileTypeAuthorizer for enforcing profile-based authorization. Users are strongly advised to upgrade to version 6.5.6 or later to mitigate the risk.