216.73.216.233

CVE-2026-40459

· Published 17/04/2026 14:16 · Modified 17/04/2026 15:38

Labels: CVE-2026-40459 2026-04-17CVE-2026-40459CWE-90[email protected]

Essential information

Published
17/04/2026 14:16
Modified
17/04/2026 15:38
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting in unauthorized LDAP queries and arbitrary directory operations. This issue was fixed in PAC4J versions 4.5.10, 5.7.10 and 6.4.1

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
pac4j / pac4j cpe:2.3:a:pac4j:pac4j:<4.5.10:*:*:*:*:*:*:*
pac4j / pac4j cpe:2.3:a:pac4j:pac4j:<5.7.10:*:*:*:*:*:*:*
pac4j / pac4j cpe:2.3:a:pac4j:pac4j:<6.4.1:*:*:*:*:*:*:*

References