Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-82461: pac4j-oidc versions before 6.5.6 allow forged tokens to gain admin rights

CVE-2026-82461 · published 5 days ago
Summary

Applications that use the pac4j‑oidc library to read user roles from Keycloak may accept fake access tokens that look valid. Because the library does not check the token’s signature, issuer, audience, or expiration, an attacker can create a token that grants administrative privileges and bypass role checks. Update to version 6.5.6 or later, or apply a patch that adds proper token verification, to stop this risk.

What to do
  • Update pac4j pac4j to version 6.5.6 or later.
Affected software
VendorProductAffected versions
pac4j pac4j < 6.5.6
Original advisory text
pac4j-oidc before 6.5.6 Privilege Escalation via Unverified Keycloak Access Token
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative roles paired with valid ID tokens to bypass authorization checks in applications relying on pac4j role validation.
Severity
8.6 High
CVSS 3.1: 8.1 (NVD)
CVSS 4.0: 8.6 (NVD)
Exploitation
EPSS <1%
Type
CWE-347Improper Verification of Cryptographic Signature
Timeline
Published29 Aug 2026
Updated2 Sep 2026
First seen29 Aug 2026
Sources
CVE-2026-82461 · MITRE
Monitor software like this
Free during beta