VORANT. Threat Intelligence Sign in Get the full feed

pac4j-jwt flaw enables authentication bypass

critical vulnerability

CVE-2026-29000 in pac4j-jwt JwtAuthenticator allows remote attackers to forge tokens using only the server's public RSA key, bypassing authentication to impersonate any user.

A critical authentication bypass vulnerability has been discovered in pac4j-jwt's JwtAuthenticator component affecting versions 4.x through 6.x. The flaw stems from improper validation of encrypted JSON Web Tokens (JWE), allowing attackers with access to the server's public RSA key to forge JWT tokens with arbitrary claims. This enables complete authentication bypass without knowledge of any secrets.

The vulnerability (CVE-2026-29000) affects all users of the pac4j security framework's JWT module across multiple major versions. Proof of concept code has been publicly released by CodeAnt AI, increasing the urgency for remediation. Successful exploitation allows unauthenticated remote attackers to authenticate as any user, including administrators, with any role.

Patches are available across all affected version lines: 4.5.9+ for 4.x, 5.7.9+ for 5.x, and 6.3.3+ for 6.x. Organizations using pac4j-jwt should prioritize immediate patching given the severity of the authentication bypass and availability of public exploit code.

Mentioned in this report

Vulnerabilities CVE-2026-29000

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-pac4j-jwt-jwtauthenticator-could-allow-for-authentication-bypass_2026-019

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free