CVE-2026-40459 Details
Description
PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting in unauthorized LDAP queries and arbitrary directory operations. This issue was fixed in PAC4J versions 4.5.10, 5.7.10 and 6.4.1
A vulnerability allowing LDAP injection has been identified in PAC4J versions 4.0 prior to 4.5.10, 5.0 prior to 5.7.10, and 6.0 prior to 6.4.1. This vulnerability arises in multiple methods where a low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters. Such injection could lead to unauthorized LDAP queries and arbitrary operations within the directory.
Users should upgrade to PAC4J version 4.5.10 or newer, 5.7.10 or newer, or 6.4.1 or newer, depending on their current version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/en/posts/2026/04/CVE-2026-40458/ | [email protected] | Third Party Advisory |
| https://www.pac4j.org/blog/security-advisory-pac4j-core-and-ldap.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-90 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| pac4j pac4j | >= 4.0.0, < 4.5.10 >= 5.0.0, < 5.7.10 >= 6.0.0, < 6.4.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 20, 2026 | Initial Analysis | [email protected] |
| Apr 17, 2026 | New CVE Received | [email protected] |