GHSA-f66h-84rm-53q7HighCVSS 8.1

pac4j-core before 6.5.6 contains an authentication bypass vulnerability in...

Published
August 29, 2026
Last Modified
August 29, 2026

🔗 CVE IDs covered (1)

📋 Description

pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger profile type by satisfying generic profile checks.

🔗 References (7)