CVE-2026-40459
EUVD-2026-2342317.04.2026, 14:16
PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting in unauthorized LDAP queries and arbitrary directory operations. This issue was fixed in PAC4J versions 4.5.10, 5.7.10 and 6.4.1
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pac4j | pac4j | 4.0.0 ≤ 𝑥 < 4.5.10 |
| pac4j | pac4j | 5.0.0 ≤ 𝑥 < 5.7.10 |
| pac4j | pac4j | 6.0.0 ≤ 𝑥 < 6.4.1 |
𝑥
= Vulnerable software versions