Vulnerability Description
PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting in unauthorized LDAP queries and arbitrary directory operations. This issue was fixed in PAC4J versions 4.5.10, 5.7.10 and 6.4.1
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pac4J | Pac4J | >= 4.0.0, < 4.5.10 |
Related Weaknesses (CWE)
References
- https://cert.pl/en/posts/2026/04/CVE-2026-40458/Third Party Advisory
- https://www.pac4j.org/blog/security-advisory-pac4j-core-and-ldap.htmlVendor Advisory
FAQ
What is CVE-2026-40459?
CVE-2026-40459 is a vulnerability with a CVSS score of 8.8 (HIGH). PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting in unauthorized LDAP q...
How severe is CVE-2026-40459?
CVE-2026-40459 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-40459?
Check the references section above for vendor advisories and patch information. Affected products include: Pac4J Pac4J.