CVE-2026-82461
Received Received - Intake

Authentication Bypass via Forged Keycloak Tokens in pac4j-oidc

Vulnerability report for CVE-2026-82461, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-29

Last updated on: 2026-08-29

Assigner: VulnCheck

Description

pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative roles paired with valid ID tokens to bypass authorization checks in applications relying on pac4j role validation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-29
Last Modified
2026-08-29
Generated
2026-08-29
AI Q&A
2026-08-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
pac4j pac4j_oidc to 6.5.6 (exc)
pac4j pac4j-core to 6.5.6 (exc)
pac4j pac4j-saml to 6.5.6 (exc)
pac4j pac4j-oidc to 6.5.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

pac4j-oidc before version 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative roles paired with valid ID tokens to bypass authorization checks in applications relying on pac4j role validation.

Detection Guidance

Check if your pac4j-oidc version is below 6.5.6. Review application logs for unauthorized role assignments or access token parsing failures. Inspect network traffic for unusual Keycloak token exchanges.

Impact Analysis

Attackers could gain unauthorized administrative access to applications using pac4j-oidc for Keycloak role validation. This could lead to privilege escalation, data breaches, or unauthorized system modifications if the forged tokens are accepted by the application.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for data protection such as GDPR and HIPAA. It undermines role-based access controls, potentially exposing personal or health information to unauthorized parties.

Mitigation Strategies

Upgrade pac4j-oidc to version 6.5.6 or later. Implement strict token validation for signatures, issuers, audiences, and expiry. Review and restrict role assignments in Keycloak configurations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82461. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart