MEDIUMVulnerability
CVE-2026-82462
pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validation. Attackers can substitute access tokens minted for other clients to create authenticated sessions without proper issuer, audience, nonce, or subject verification.
Properties
- severity
- MEDIUM
- score
- 6.5
- epss_score
- 0.00133
- cve_id
- CVE-2026-82462
- signal_observed_at
- 2026-09-15T21:12:48+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- published_at
- 2026-08-29T17:17:58.350
- last_modified
- 2026-09-10T19:54:25.810
- epss_percentile
- 0.03212
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (1)
→[Weakness]Insufficient Verification of Data Authenticity
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph