CVE-2026-40459

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
17/04/2026
Last modified:
20/04/2026

Description

PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting in unauthorized LDAP queries and arbitrary directory operations.<br /> <br /> This issue was fixed in PAC4J versions 4.5.10, 5.7.10 and 6.4.1

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:* 4.0.0 (including) 4.5.10 (excluding)
cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:* 5.0.0 (including) 5.7.10 (excluding)
cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:* 6.0.0 (including) 6.4.1 (excluding)