Beveiligingsadvies

CVE-2026-82463

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-29 16:35:26
Laatst bijgewerkt 2026-09-02 18:09:56
Toegewezen door VulnCheck
CVSS-score 8.6
Status PUBLISHED

Beschrijving

pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger profile type by satisfying generic profile checks.