SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-82463

HIGH · CVSS 8.1 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-29 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

An authentication bypass vulnerability in pac4j-core versions prior to 6.5.6 allows attackers to exploit reversed profile type validation in the CheckProfileTypeAuthorizer, enabling them to gain unauthorized access to resources that require a stronger profile type. This issue poses a significant risk to applications relying on pac4j for authentication, particularly those managing sensitive user data. Organizations utilizing affected versions should prioritize immediate updates to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82463
Severity
HIGH
CVSS
8.1
EPSS
0.30%

Original NVD Description

pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger profile type by satisfying generic profile checks.