PatchSiren cyber security CVE debrief
CVE-2026-82464 pac4j CVE debrief
The CVE record for CVE-2026-82464 was published on 2026-08-29T17:17:58.640Z and has not been modified since then. The pac4j-core library before version 6.5.6 contains an open redirect vulnerability in the DefaultLogoutLogic.perform() method. This vulnerability allows attackers to craft logout links with backslash-prefixed external hosts that browsers normalize into network-path references, potentially redirecting victims to attacker-controlled sites after logout. Affected product deployments should be identified and patched or mitigated. Security teams and administrators responsible for pac4j-core or systems using this library should be aware of this vulnerability and take necessary actions to mitigate the risk.
- Vendor
- pac4j
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-29
- Original CVE updated
- 2026-08-29
- Advisory published
- 2026-08-29
- Advisory updated
- 2026-08-29
Who should care
Security teams and administrators responsible for pac4j-core or systems using this library should be aware of this vulnerability and take necessary actions to mitigate the risk. They should review affected product deployments, implement additional security measures, and conduct thorough inventory checks to identify potentially affected systems. Vulnerability management and security teams should prioritize patching and compensating controls for exposed systems while remediation is scheduled and verified. Monitoring and detection teams should check relevant logs for exposed assets that need extra review. Asset owners should track exceptions, retest remediated assets, and close the item only after evidence is documented. Operators of affected platforms should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Security teams should consider compensating controls for exposed systems while remediation is scheduled and verified. They should also review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. This may involve confirming whether affected product deployments exist in managed environments and assigning an owner for follow-up. Finally, they should review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review. Security teams and administrators should also track exceptions, retest remediated assets, and close the item only after evidence is documented. This vulnerability affects pac4j-core library users who have not applied patches or updates to version 6.5.6 or later. Security teams and administrators should prioritize patching and compensating controls for exposed systems while remediation is scheduled and verified. They should also consider compensating controls, such as web application firewalls, to mitigate potential attacks. Security teams and administrators should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should plan vendor-supported updates or mitigations,
Technical summary
The pac4j-core library before version 6.5.6 contains an open redirect vulnerability in the DefaultLogoutLogic.perform() method. This vulnerability allows attackers to craft logout links with backslash-prefixed external hosts that browsers normalize into network-path references, potentially redirecting victims to attacker-controlled sites after logout. Affected product deployments should be identified and patched or mitigated.
Defensive priority
Medium-priority defensive actions are recommended due to the CVSS score of 5.3 and the potential for attackers to craft logout links that redirect victims to attacker-controlled sites after logout.
Recommended defensive actions
- Apply patches or updates to pac4j-core to version 6.5.6 or later
- Implement additional security measures to monitor and restrict logout redirects
- Conduct thorough inventory checks to identify potentially affected systems
- Consider compensating controls, such as web application firewalls, to mitigate potential attacks
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
Evidence is based on official CVE Program and NVD records, as well as source references from [email protected]. The open redirect vulnerability in pac4j-core before 6.5.6 is confirmed, but details on affected products and versions are limited. Defenders should verify affected product deployments, review official advisories, and track exceptions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-82464 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-82464
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-82464 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-82464
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/pac4j/pac4j
-
Source reference
Unverified legacy reference
URL: https://github.com/pac4j/pac4j/blob/pac4j-parent-6.5.5/pac4j-core/src/main/java/org/pac4j/core/engine/DefaultLogoutLogic.java
-
Source reference
Unverified legacy reference
URL: https://github.com/pac4j/pac4j/commit/2270c3ff70e93cc43831e75702acd5135531237e
-
Source reference
Unverified legacy reference
URL: https://www.pac4j.org/blog/security-advisory-pac4j-core-oidc-saml.html
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/pac4j-core-before-6.5.6-open-redirect-via-backslash-logout
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.