CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-29000

Critical · CVSS 9.1

pac4j-jwt — JWT authentication bypass via JWE-wrapped PlainJWT (improper signature verification, CWE-347)

CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-347

Description

pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens. Attackers who possess the server's RSA public key can create a JWE-wrapped PlainJWT with arbitrary subject and role claims, bypassing signature verification to authenticate as any user including administrators.

Search profile — drives PoC discovery

Symbols JwtAuthenticatorPlainJWTJWEJWEObjectSignedJWTJWTClaimsSetpac4j-jwtorg.pac4j.jwtJwtGeneratorvalidateSignaturegetClaimsSetencryptedJWTRSAEncrypterRSADecrypterPlainHeaderAlgorithm.NONE
Keywords CVE-2026-29000pac4j-jwt authentication bypassJwtAuthenticator PlainJWT bypasspac4j JWE wrapped PlainJWTpac4j RSA public key forge JWTpac4j-jwt signature verification bypasspac4j authentication bypass exploitpac4j-jwt PoCpac4j JWE PlainJWT arbitrary claimspac4j-jwt 4.5.9 5.7.9 6.3.3
Versions: < 4.5.9, < 5.7.9, < 6.3.3

Ranked PoCs (22) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

Maven org.pac4j:pac4j-jwt 0 → 4.5.9
Maven org.pac4j:pac4j-jwt 5.0.0-RC1 → 5.7.9
Maven org.pac4j:pac4j-jwt 6.0.4.1 → 6.3.3

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z