PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-82464 pac4j CVE debrief

The CVE record for CVE-2026-82464 was published on 2026-08-29T17:17:58.640Z and has not been modified since then. The pac4j-core library before version 6.5.6 contains an open redirect vulnerability in the DefaultLogoutLogic.perform() method. This vulnerability allows attackers to craft logout links with backslash-prefixed external hosts that browsers normalize into network-path references, potentially redirecting victims to attacker-controlled sites after logout. Affected product deployments should be identified and patched or mitigated. Security teams and administrators responsible for pac4j-core or systems using this library should be aware of this vulnerability and take necessary actions to mitigate the risk.

Vendor
pac4j
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-29
Original CVE updated
2026-08-29
Advisory published
2026-08-29
Advisory updated
2026-08-29

Who should care

Security teams and administrators responsible for pac4j-core or systems using this library should be aware of this vulnerability and take necessary actions to mitigate the risk. They should review affected product deployments, implement additional security measures, and conduct thorough inventory checks to identify potentially affected systems. Vulnerability management and security teams should prioritize patching and compensating controls for exposed systems while remediation is scheduled and verified. Monitoring and detection teams should check relevant logs for exposed assets that need extra review. Asset owners should track exceptions, retest remediated assets, and close the item only after evidence is documented. Operators of affected platforms should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Security teams should consider compensating controls for exposed systems while remediation is scheduled and verified. They should also review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. This may involve confirming whether affected product deployments exist in managed environments and assigning an owner for follow-up. Finally, they should review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review. Security teams and administrators should also track exceptions, retest remediated assets, and close the item only after evidence is documented. This vulnerability affects pac4j-core library users who have not applied patches or updates to version 6.5.6 or later. Security teams and administrators should prioritize patching and compensating controls for exposed systems while remediation is scheduled and verified. They should also consider compensating controls, such as web application firewalls, to mitigate potential attacks. Security teams and administrators should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should plan vendor-supported updates or mitigations,

Technical summary

The pac4j-core library before version 6.5.6 contains an open redirect vulnerability in the DefaultLogoutLogic.perform() method. This vulnerability allows attackers to craft logout links with backslash-prefixed external hosts that browsers normalize into network-path references, potentially redirecting victims to attacker-controlled sites after logout. Affected product deployments should be identified and patched or mitigated.

Defensive priority

Medium-priority defensive actions are recommended due to the CVSS score of 5.3 and the potential for attackers to craft logout links that redirect victims to attacker-controlled sites after logout.

Recommended defensive actions

  • Apply patches or updates to pac4j-core to version 6.5.6 or later
  • Implement additional security measures to monitor and restrict logout redirects
  • Conduct thorough inventory checks to identify potentially affected systems
  • Consider compensating controls, such as web application firewalls, to mitigate potential attacks
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

Evidence is based on official CVE Program and NVD records, as well as source references from [email protected]. The open redirect vulnerability in pac4j-core before 6.5.6 is confirmed, but details on affected products and versions are limited. Defenders should verify affected product deployments, review official advisories, and track exceptions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-82464 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-82464

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-82464 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-82464

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.