{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3apac4jpac4j-core/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pac4j:pac4j-core:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-82463"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["pac4j-core (\u003c 6.5.6)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["pac4j"],"content_html":"\u003cp\u003eThe pac4j-core library, commonly used for security and authentication in Java-based web applications, contains a critical authentication bypass vulnerability identified as CVE-2026-82463. The vulnerability exists within the CheckProfileTypeAuthorizer component. Due to a logical error in the validation logic, the profile type check is effectively reversed. This flaw allows an attacker to authenticate using a lower-privileged or weaker client and successfully bypass authorization checks intended for higher-privileged profiles.\u003c/p\u003e\n\u003cp\u003eBy exploiting this flaw, unauthenticated or low-privilege actors can gain access to sensitive application resources that should be restricted to specific, stronger profile types. This vulnerability affects all pac4j-core versions prior to 6.5.6. Given the library's integration into web frameworks, this poses a significant risk to application authorization policies. Defenders should identify applications utilizing vulnerable versions of the library and prioritize the upgrade to version 6.5.6 or later.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-82463 permits unauthorized access to resources and data restricted by the pac4j-core authorization framework. This bypass undermines the integrity of access control mechanisms within affected web applications, potentially leading to unauthorized data exposure, privilege escalation, or administrative action performance by unauthorized users. The extent of the damage depends on the specific resources protected by the affected authorizer within the target application.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the pac4j-core dependency to version 6.5.6 or later in all Java-based applications.\u003c/li\u003e\n\u003cli\u003eReview application authorization policies that utilize CheckProfileTypeAuthorizer to confirm they are not relying on default behavior if currently running a vulnerable version.\u003c/li\u003e\n\u003cli\u003eAudit web application logs for unexpected access patterns where users with low-privilege sessions are accessing endpoints protected by CheckProfileTypeAuthorizer.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-29T17:40:55Z","date_published":"2026-08-29T17:40:55Z","id":"https://feed.craftedsignal.io/briefs/2026-08-pac4j-auth-bypass/","summary":"An authentication bypass vulnerability in pac4j-core versions prior to 6.5.6 caused by flawed validation logic in CheckProfileTypeAuthorizer allows unauthorized access to restricted resources.","title":"Authentication Bypass Vulnerability in pac4j-core","url":"https://feed.craftedsignal.io/briefs/2026-08-pac4j-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:pac4j:pac4j-Core:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}