← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 29, 2026 · 17:17via CVEFeed

CVE-2026-82461 - pac4j-oidc before 6.5.6 Privilege Escalation via Unverified Keycloak Access Token

Brief

CVE ID : CVE-2026-82461

Published : Aug. 29, 2026, 5:17 p. m.

  • 3 hours, 57 minutes ago

Description : pac4j-oidc before 6.

  • 6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative roles paired with valid ID tokens to bypass authorization checks in applications relying on pac4j role validation.

Severity: 8.1

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed