pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validation. Attackers can substitute access tokens minted for other clients to create authenticated sessions without proper issuer, audience, nonce, or subject verification.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-29 17:17
Updated : 2026-09-10 19:54
NVD link : CVE-2026-82462
Mitre link : CVE-2026-82462
CVE.ORG link : CVE-2026-82462
JSON object : View
Products Affected
No product.
CWE
CWE-345
Insufficient Verification of Data Authenticity
