CVE-2026-82461
Received
Received - Intake
Authentication Bypass via Forged Keycloak Tokens in pac4j-oidc
Vulnerability report for CVE-2026-82461, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-29
Last updated on: 2026-08-29
Assigner: VulnCheck
Description
Description
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative roles paired with valid ID tokens to bypass authorization checks in applications relying on pac4j role validation.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| pac4j | pac4j_oidc | to 6.5.6 (exc) |
| pac4j | pac4j-core | to 6.5.6 (exc) |
| pac4j | pac4j-saml | to 6.5.6 (exc) |
| pac4j | pac4j-oidc | to 6.5.6 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-347 | The product does not verify, or incorrectly verifies, the cryptographic signature for data. |