Improper verification of cryptographic signature in pac4j - CVE-2026-29000
Published: March 9, 2026 / Updated: May 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication checks.
The vulnerability exists due to an error in JwtAuthenticator when processing encrypted JWTs. A remote non-authenticated attacker with possession of the server's RSA public key can create a JWE-wrapped PlainJWT with arbitrary subject and role claims, bypass signature verification and authenticated as any user including administrators.
Affected software
How to mitigate CVE-2026-29000
Links to Public Exploits and PoC-codes
- Exploit #12731 - CVE-2026-29000-PoC-Exploit (CVE-2026-29000 – pac4j-jwt Authentication Bypass (? CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets. Keep-alive, proxy, custom JWKS.⚙️ Educational PoC Exploit tool.) (May 22, 2026)
- Exploit #12546 - Cve_2026_29000_exploit () (April 1, 2026)
- Exploit #12524 - cve-2026-29000 (cve-2026-29000 exploit) (April 1, 2026)