CVE-2026-29000
Critical · CVSS 9.1pac4j-jwt — JWT authentication bypass via JWE-wrapped PlainJWT (improper signature verification, CWE-347)
- CVSS
- 9.1
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-347
Description
pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens. Attackers who possess the server's RSA public key can create a JWE-wrapped PlainJWT with arbitrary subject and role claims, bypassing signature verification to authenticate as any user including administrators.
Search profile — drives PoC discovery
Ranked PoCs (22) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 8
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 3
- ★ 2
- ★ 1recent activitygh_search · Python
- ★ 1
- ★ 1recent activitygh_search · Python
- ★ 1
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 0
- ★ 3tc4dy/CVE-2026-29000-PoC-Exploit needs reviewgh_search · Python
- ★ 1dua2z3rr/CVE-2026-29000-PoC needs reviewgh_search · Python
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
Affected packages
| Maven | org.pac4j:pac4j-jwt | 0 → 4.5.9 |
| Maven | org.pac4j:pac4j-jwt | 5.0.0-RC1 → 5.7.9 |
| Maven | org.pac4j:pac4j-jwt | 6.0.4.1 → 6.3.3 |
References
Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z