pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative roles paired with valid ID tokens to bypass authorization checks in applications relying on pac4j role validation.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-29 17:17
Updated : 2026-09-10 19:54
NVD link : CVE-2026-82461
Mitre link : CVE-2026-82461
CVE.ORG link : CVE-2026-82461
JSON object : View
Products Affected
No product.
CWE
CWE-347
Improper Verification of Cryptographic Signature
