Zero-DayCVE-2026-29000CVSS 10

CVE-2026-29000: pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authenticati

NVD/CVE · [email protected]3/4/2026, 10:16:19 PM 100 points
View Original Source

Summary

pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens. Attackers who possess the server's RSA public key can create a JWE-wrapped PlainJWT with arbitrary subject and role claims, bypassing signature verification to authenticate as any user including administrators.

Tags

#CVE-2026-29000#cve

Metadata

Article ID
#300154
Source
NVD/CVE
Scraped At
3/7/2026, 6:11:51 PM
URL Hash
3bf7e01515521171…