← Vulnerability feed

Vulnerability record · CVE-2026-40459 · published 17 April 2026

CVE-2026-40459: Pac4j ldap injection vulnerability

Pac4j · Pac4j

PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting in unauthorized LDAP queries and arbitrary directory operations. This issue was fixed in PAC4J versions 4.5.10, 5.7.10 and 6.4.1

8.7 CVSS 4.0 High EPSS 0.68% · top 49.7% CWE-90 · LDAP injection
8.7CVSS 4.0 base score
0.68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting in unauthorized LDAP queries and arbitrary directory operations. This issue was fixed in PAC4J versions 4.5.10, 5.7.10 and 6.4.1

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-40459 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2021-44878Pac4j improper verification of cryptographic signature vulnerabilityIf an OpenID Connect provider supports the "none" algorithm (i.e., tokens with no signature), pac4j v5.3.0 (and prior) does not refuse it without an …EPSS 0.90%7.0CVE-2026-40458Pac4j cross-site request forgery vulnerabilityPAC4J is vulnerable to Cross-Site Request Forgery (CSRF). A malicious attacker can craft a specially designed website which, when visited by a user, …EPSS 0.18%4.9CVE-2019-10755Pac4j vulnerabilityThe SAML identifier generated within SAML2Utils.java was found to make use of the apache commons-lang3 RandomStringUtils class which makes them predi…EPSS 1.1%7.8CVE-2026-85880Windows ALPC heap buffer overflow allows local privilege escalationA heap-based buffer overflow in the Windows ALPC subsystem, combined with use of an uninitialized resource, lets an attacker with existing local acce…KEVEPSS 3.6%analysed9.3CVE-2025-5777Citrix NetScaler ADC/Gateway memory overread via insufficient input validationCVE-2025-5777 is an insufficient input validation flaw in Citrix NetScaler ADC and NetScaler Gateway that causes a memory overread when the appliance…KEVEPSS 100%analysed5.5CVE-2024-50302Linux kernel HID core uninitialized report buffer leaks kernel memoryThe Linux kernel HID core allocates a report buffer without zero-initializing it, so residual kernel memory can be exposed through crafted HID report…KEVEPSS 0.81%analysed5.5CVE-2024-29745Android Pixel firmware uninitialized data information disclosureCVE-2024-29745 is an information disclosure flaw in Android on Pixel devices caused by use of uninitialized data (CWE-908). A local attacker can read…KEVEPSS 0.48%analysed

Source: NIST National Vulnerability Database (record CVE-2026-40459), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.