pac4j-oidc 在 6.5.6 版本之前,在提取 Keycloak 的 realm 和客户端角色时,未能验证访问令牌(access token)的签名、签发者(issuer)、受众(audience)或过期时间。攻击者可以伪造带有管理员角色的访问令牌,并搭配有效的 ID 令牌,从而绕过依赖 pac4j 角色验证的应用程序中的授权检查。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82463 | 8.1 HIGH | pac4j-core before 6.5.6 Authorization Bypass via Reversed Profile Type Check |
| CVE-2026-82462 | 6.5 MEDIUM | pac4j-oidc before 6.5.6 Authentication Bypass via Access Token Substitution |
| CVE-2026-82464 | 6.1 MEDIUM | pac4j-core before 6.5.6 Open Redirect via Backslash Logout |
| CVE-2026-82465 | 5.3 MEDIUM | pac4j-saml before 6.5.6 Session Destruction via Unsigned LogoutRequest |
No comments yet