Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40458

22
FAUCET Score

CVE-2026-40458 is a Cross-Site Request Forgery (CSRF) vulnerability in PAC4J that allows attackers to bypass CSRF token protection through hash collisions in the String.hashCode() function. An attacker can craft a malicious website that, when visited by a user, automatically submits forged requests with tokens whose hashes collide with legitimate CSRF tokens, effectively reducing token security to 32 bits. The attacker requires no prior knowledge of the victim's actual token to execute the attack. The vulnerability carries a CVSS score of 6.5 (Medium) with a network-based attack vector requiring minimal complexity and user interaction. While confidentiality is not impacted, the integrity impact is high, as attackers can perform unauthorized state-changing operations including profile updates, password changes, and account linking without victim consent. PAC4J versions 5.7.10 and 6.4.1 or later contain the fix. Exploitation of this vulnerability is not currently documented in active exploitation campaigns. The EPSS score of 0.00017 indicates extremely low probability of exploitation in the wild relative to other vulnerabilities. CVE-2026-40458 does not appear on CISA's Known Exploited Vulnerabilities catalog and remains on the inactive Hot List, suggesting limited community attention and no publicly available exploit code at this time.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.0, < 5.7.10CPE match
cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:*
>= 6.0, < 6.4.1CPE match
cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:*
>= 5.0.0, < 5.7.10CPE matchmatch criteria
cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:*
> 6.0.0, < 6.4.1CPE matchmatch criteria
cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.0HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
NONE
VS Integrity
HIGH
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
6.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 5th percentile among its peer group of 26,219 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

mavenpatch availablevia ghsa
Product: org.pac4j:pac4j-coreFixed in: 5.7.10
mavenpatch availablevia ghsa
Product: org.pac4j:pac4j-coreFixed in: 6.4.1

Vendor Advisories (1)

mavenGHSA-xw5c-jc7x-gf75high

PAC4J has a Cross-Site Request Forgery (CSRF) Vulnerability

Apr 17, 2026

References

cert.pl / en/posts/2026/04/CVE-2026-40458
Third Party Advisory
pac4j.org / blog/security-advisory-pac4j-core-and-ldap.html
Vendor Advisory