← Back
Auth / Identity
CVE-2026-82463 high CVSS 8.1

pac4j-core before 6.5.6 contains an authentication bypass vulnerability in...

Summary

pac4j-core before 6.5.6 contains an authentication bypass vulnerability in...

AI summary openai / gpt-4o

pac4j-coreのバージョン6.5.6未満には、CheckProfileTypeAuthorizerの認証バイパス脆弱性があります。これにより、攻撃者はより弱いクライアントを通じて認証し、より強力なプロファイルタイプを必要とするリソースにアクセスすることができます。
❓ What is the problem
pac4j-coreのCheckProfileTypeAuthorizerにおける認証バイパス脆弱性。
📍 Affected scope
pac4j-coreバージョン6.5.6未満。
🔥 Severity
攻撃者が認証をバイパスし、強力なプロファイルタイプが要求されるリソースにアクセス可能になるため、深刻なリスクがあります。
🔧 How to fix
pac4j-coreをバージョン6.5.6以上にアップデートしてください。
🛡️ Workaround
情報なし
🔍 Detection
情報なし

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →