CVE-2026-29000Disclosure

CRITICALCVSS 9.3 · CRITICAL

Exploitation observed; activity peaked at 18 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens. Attackers who possess the server's RSA public key can create a JWE-wrapped PlainJWT with arbitrary subject and role claims, bypassing signature verification to authenticate as any user including administrators.

8.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 46 mentions across 15 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 9 signals
  • Patch or workaround mentioned in 14 signals
  • Technical details provided in 33 signals
  • Disclosure: 18 classified signals
  • General: 9 classified signals
  • Peaked 13d ago at 18 mentions (2026-03-05); latest day: 1
  • 46 total mentions across 15 days

Deep dive

Activity timeline46 mentions / 15d
0591418Mentions · 2026-03-04: 5Mentions · 2026-03-05: 18Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Mentions · 2026-03-10: 2Mentions · 2026-03-11: 4Mentions · 2026-03-12: 2Mentions · 2026-03-13: 2Mentions · 2026-03-16: 3Mentions · 2026-03-18: 2Mentions · 2026-03-29: 1Mentions · 2026-03-30: 2Mentions · 2026-04-07: 1Mentions · 2026-07-13: 1Mentions · 2026-09-29: 1PoC Mentioned / Linked · 2026-03-05: 3PoC Mentioned / Linked · 2026-03-06: 1PoC Mentioned / Linked · 2026-03-07: 1PoC Mentioned / Linked · 2026-03-13: 1PoC Mentioned / Linked · 2026-03-16: 2PoC Mentioned / Linked · 2026-03-30: 1Exploit Tool / Code · 2026-03-05: 1Exploit Tool / Code · 2026-03-06: 1Exploit Tool / Code · 2026-03-16: 1Exploit Tool / Code · 2026-03-30: 1Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-04-07: 1Patch / Workaround · 2026-03-04: 1Patch / Workaround · 2026-03-05: 2Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-11: 2Patch / Workaround · 2026-03-12: 2Patch / Workaround · 2026-03-13: 1Patch / Workaround · 2026-03-16: 1Patch / Workaround · 2026-03-18: 2Patch / Workaround · 2026-03-29: 1Patch / Workaround · 2026-03-30: 1Technical Details · 2026-03-04: 4Technical Details · 2026-03-05: 12Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 1Technical Details · 2026-03-10: 2Technical Details · 2026-03-11: 2Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 2Technical Details · 2026-03-16: 3Technical Details · 2026-03-29: 1Technical Details · 2026-03-30: 2Technical Details · 2026-04-07: 1Technical Details · 2026-07-13: 103-0403-0503-0603-0703-1003-1103-1203-1303-1603-1803-2903-3004-0707-1309-29
Signal classification5 categories
Disclosure
1840.0%
Patch
1124.4%
General
920.0%
PoC
511.1%
Active Exploitation
24.4%
Referenced assets30 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-045
Disclosure3General1Patch1
2026-03-0518
Disclosure9General6Patch1PoC2
2026-03-061
PoC1
2026-03-071
Disclosure1
2026-03-102
Disclosure1Patch1
2026-03-114
Active Exploitation1Disclosure1Patch2
2026-03-122
Patch2
2026-03-132
Disclosure2
2026-03-163
General2PoC1
2026-03-182
Patch2
2026-03-291
Patch1
2026-03-302
Patch1PoC1
2026-04-071
Active Exploitation1
2026-07-131
Disclosure1
Full discourse20 posts
  • Hack The Box@hackthebox_eu
    General

    New CVE Machine 🚨 Principal is now available for you to explore a critical identity boundary flaw. This new free retired Machine is centered on CVE-2026-29000, a newly disclosed authentication bypass in the pac4j-jwt library. Since Pac4j is used to implement major identity flows like OAuth, SAML, and JWT authentication, this vulnerability allows attackers to bypass core security controls in Java applications. Assigned a CVSS score of 9.1, it highlights the far-reaching consequences when a system verifies a cryptographic envelope but fails to validate the claim inside. Sharpen your skills now: https://okt.to/XmS2Hn #HackTheBox #CVE #Cybersecurity #Pentesting #RedTeam #Infosec #Cryptography

    Post summary

    The announcement highlights a new learning machine for CVE‑2026‑29000, providing technical details of the authentication bypass and a link to the lab, but does not present exploit code, active attacks, or patch information.

    2100120186.4K
    241.6K followersView on X
  • Brut 🇮🇳@wtf_yodhha
    PoC

    CVE-2026-29000: Critical Auth Bypass in pac4j-jwt: Full PoC Using Only a Public Key https://www.codeant.ai/security-research/pac4j-jwt-authentication-bypass-public-key #BugBounty #bugbountytips

    Post summary

    The post announces CVE‑2026‑29000, a critical auth bypass in pac4j‑jwt, and provides a full PoC that exploits it using only a public key, with no hints of active exploitation or a patch.

    113061513.8K
    7.0K followersView on X
  • blueblue@piedpiper1616
    PoC

    CVE-2026-29000: Critical Auth Bypass in pac4j-jwt: Full PoC Using Only a Public Key - https://www.codeant.ai/security-research/pac4j-jwt-authentication-bypass-public-key

    Post summary

    The post announces a critical authentication bypass (CVE-2026-29000) in pac4j-jwt, shares a full PoC that leverages only a public key, and links to detailed research.

    012034173.2K
    5.5K followersView on X
  • 0xdf@0xdf_
    PoC

    Principal from @hackthebox_eu features a pac4j JWT authentication bypass (CVE-2026-29000) to forge admin tokens using just the public key, password reuse to SSH, and abusing an SSH CA private key to sign a root certificate. https://0xdf.gitlab.io/2026/03/30/htb-principal.html

    Post summary

    The write‑up details a CVE‑2026‑29000 JWT authentication bypass that allows forging admin tokens with only the public key, password reuse to SSH, and abuse of an SSH CA private key—providing a functional exploitation path but no evidence of active attacks or available patches.

    0403892.3K
    26.5K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    A critical 10.0 CVSS flaw (CVE-2026-29000) in the pac4j-jwt library allows attackers to forge JWTs and bypass authentication. Patch immediately. #pac4j #JWTSecurity #CVE #CyberSecurity #InfoSec #JavaSecurity #Vulnerability #AppSec #AuthenticationBypass https://securityonline.info/critical-10-0-cvss-flaw-in-pac4j-jwt-lets-hackers-forge-admin-tokens/

    Post summary

    The tweet announces CVE‑2026‑29000 as a critical flaw that lets attackers forge JWTs and bypass authentication, and urges users to patch immediately.

    140138949
    10.5K followersView on X
  • Autumn Good@autumn_good_35
    PoC

    『An attacker with nothing more than your server's RSA public key - <snip> - can forge a JWT token with arbitrary claims and authenticate as any user, with any role,』 CVE-2026-29000: Critical Auth Bypass in pac4j-jwt: Full PoC Using Only a Public Key https://www.codeant.ai/security-research/pac4j-jwt-authentication-bypass-public-key

    Post summary

    A Proof of Concept demonstrates that an attacker can forge JWT tokens using only the RSA public key to bypass authentication in pac4j-jwt (CVE‑2026‑29000).

    021521.0K
    6.7K followersView on X
  • Amartya Jha@amartya_jha_
    Disclosure

    @CodeAntAI's code reviewer just found a zero day security vulnerability, with a CVSS score of 10.0 (maximum) CVE-2026-29000. Published today. A complete authentication bypass in pac4j-jwt, one of the most widely used Java auth libraries. An attacker can craft a token and log in as any user, including admin. The only thing they need? The server's RSA public key. The one that's public by design. The root cause: the library trusts a type of token that the JWT spec technically allows but that should never bypass signature verification. When it receives one, it skips the entire signature check and builds a fully authenticated session from whatever the attacker put in the token. Not a human researcher. Not a pen tester. An AI code reviewer. We don't publish benchmarks. We publish CVEs. This is one of 87, zero day vulnerabilities we published, more dropping soon! Kudos to @VulnCheckAI for expediting the CVE assignment. @CVEnew

    Post summary

    An AI code reviewer disclosed a critical authentication bypass in pac4j-jwt (CVE-2026-29000), noting a CVSS 10.0 score and detailed vulnerability behavior, but provides no PoC, exploitation tools, or patch information.

    21070611
    958 followersView on X
  • maru@maru1151157
    Disclosure

    🚨 CVE-2026-29000 (CVSS: 10.0) pac4j-jwt 4.5.8以下、5.7.8以下、6.3.2以下のJwtAuthenticatorで、RSA公開鍵を持つ攻撃者がJWEで暗号化したJWTを改ざんし、認証回避可能。管理者アカウントの乗っ取りが可能。 https://maruomosquit.com/vulnerability/CVE-2026-29000/ #脆弱性 #セキュリティ

    Post summary

    The post announces CVE-2026-29000, a critical authentication bypass in pac4j-jwt with a CVSS score of 10.0, allowing attackers to modify JWE‑encrypted JWTs and take over admin accounts.

    02070372
    1.5K followersView on X
  • dbugs@ptdbugs
    Disclosure

    📌 Authentication bypass in pac4j-jwt via public key CodeAnt AI researchers have demonstrated that the pac4j-jwt (Java) library improperly verifies JWT signatures, allowing a public key to be used as a private one. The vulnerability, tracked as CVE-2026-29000 (CVSS 10.0), allows authentication bypass and token issuance on behalf of any user, including administrators. An attacker only needs access to the public key to generate a valid token and gain full access without knowledge of the private key. This issue exists in the default pac4j-jwt configuration and requires no elevated privileges for exploitation. 📎 Article: https://www.codeant.ai/security-research/pac4j-jwt-authentication-bypass-public-key #dbugs_attacks

    Post summary

    CodeAnt AI researchers disclosed CVE-2026-29000, a pac4j‑jwt authentication bypass that allows attackers to use a public key as a private key to forge tokens. No active exploitation or patch information has been mentioned.

    01043146
    592 followersView on X
  • Helios Mier@hmier
    General

    👀👀👀👀👀 CVE-2026-29000

    Post summary

    The tweet merely references CVE-2026-29000 with no additional details, leaving the nature of the vulnerability unclear.

    11051250
    1.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29000 pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remo… https://www.cve.org/CVERecord?id=CVE-2026-29000

    Post summary

    CVE-2026-29000 is disclosed as an authentication-bypass flaw in pac4j-jwt's JwtAuthenticator affecting versions prior to 4.5.9, 5.7.9, and 6.3.3, though no PoC, exploit, or patch details are provided.

    12140501
    56.6K followersView on X
  • John Keese 🇺🇦🌻@JFKeese
    General

    CVE-2026-29000

    Post summary

    The text contains only the CVE identifier CVE-2026-29000 without additional details.

    03040256
    139 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-29000 - Critical pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge... https://www.thehackerwire.com/vulnerability/CVE-2026-29000/ https://t.co/GPrNPeTxKr

    Post summary

    The post discloses a critical authentication bypass flaw in pac4j-jwt, specifying vulnerable versions and the nature of the issue, but provides no PoC, exploit, or mitigation details.

    11041214
    124 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: Exploit for CVE-2026-29000 Intel Report: https://ift.tt/gdIVTQK

    Post summary

    A threat alert indicates the existence of an exploit for CVE-2026-29000, with an Intel report link provided but no exploit code, technical details, or patch information.

    02040232
    343 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-29000: CRITICAL] Security alert! Vulnerability found in pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 allows attackers to forge authentication tokens using encrypted JWTs. Update recommended!#cve,CVE-2026-29000,#cybersecurity https://cvefind.com/CVE-2026-29000

    Post summary

    The alert highlights a critical CVE-2026-29000 in pac4j-jwt that allows attackers to forge authentication tokens using encrypted JWTs, recommending users update to supported versions.

    11130303
    595 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-29000 pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remo… https://www.cve.org/CVERecord?id=CVE-2026-29000 ----- Traducción: CVE-2026-29000 pac… http://infoflow.cloud`

    Post summary

    This post announces CVE‑2026‑29000, describing an authentication bypass in pac4j‑jwt’s JwtAuthenticator that affects versions prior to 4.5.9, 5.7.9, and 6.3.3, and links to the official CVE record.

    12030204
    55 followersView on X
  • Muzakir@muzakirbloch1
    Disclosure

    CVE-2026-29000 (CVSS 10.0), this is the kind of auth bypass that's hiding in every bug bounty . This is a logic flaw, not an injection or a memory bug. No scanner finds it. You find it by understanding the JWT spec . https://www.codeant.ai/security-research/pac4j-jwt -authentication-bypass-public-key https://t.co/2ZtTyzP5xL

    Post summary

    The text announces a newly discovered auth bypass vulnerability (CVE-2026-29000) with a CVSS score of 10.0, detailing it as a logic flaw tied to JWT handling and linking to a research page, but it does not mention active exploitation, patches, or exploit code.

    02030155
    1 followersView on X
  • UltraViolet Cyber@uv_cyber
    Disclosure

    CVE-2026-29000 is a critical pac4j-jwt vulnerability that allows forged JWTs to be treated as valid authentication. In affected configurations, attackers can bypass signature verification and impersonate arbitrary users. Read the advisory: https://www.uvcyber.com/resources/reports/threat-advisory-pac4j-jwt-vulnerability https://t.co/bo0LmWmH3h

    Post summary

    The advisory announces a critical pac4j‑jwt vulnerability that lets forged JWTs be accepted as valid authentication, but it does not mention PoC, exploit tools, or patches.

    02030238
    46 followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    【部品の脆弱性】pac4jの重大(Critical)な脆弱性CVE-2026-29000による影響を受けるパッケージが追加で18個発覚。Sonatype社報告。記事には具体的影響パッケージの記載はされていない。 https://www.sonatype.com/blog/pac4j-cve-2026-29000-sonatype-finds-19-additional-packages

    Post summary

    Sonatype announced that 19 additional packages are affected by the critical CVE‑2026‑29000 in pac4j, but no specific package list, technical details, or mitigation information was provided.

    101201.5K
    7.3K followersView on X
  • ‘BugBounty Writeups’@bbwriteup
    Disclosure

    "Signed, But Not Validated: Why CVE-2026–29000 Exposes JWT’s Weak Spot (CVSS 10)" by Amitishacked #BugBounty #Cybersecurity #Hacking #InfoSec https://medium.com/@amitgy04/signed-but-not-validated-why-cve-2026-29000-exposes-jwts-weak-spot-7f5c8b9b73c3

    Post summary

    Article announces the existence of CVE-2026-29000, highlighting its CVSS 10 score and impact on JWT signature validation, but does not provide PoC, exploit details, patches, or evidence of active exploitation.

    02020234
    494 followersView on X

Explore more