Hack The Box[verified]@hackthebox_euGeneral
The announcement highlights a new learning machine for CVE‑2026‑29000, providing technical details of the authentication bypass and a link to the lab, but does not present exploit code, active attacks, or patch information.
Amartya Jha[verified]@amartya_jha_Disclosure
An AI code reviewer disclosed a critical authentication bypass in pac4j-jwt (CVE-2026-29000), noting a CVSS 10.0 score and detailed vulnerability behavior, but provides no PoC, exploitation tools, or patch information.
maru[verified]@maru1151157Disclosure
The post announces CVE-2026-29000, a critical authentication bypass in pac4j-jwt with a CVSS score of 10.0, allowing attackers to modify JWE‑encrypted JWTs and take over admin accounts.
dbugs[verified]@ptdbugsDisclosure
CodeAnt AI researchers disclosed CVE-2026-29000, a pac4j‑jwt authentication bypass that allows attackers to use a public key as a private key to forge tokens. No active exploitation or patch information has been mentioned.
kokumօtօ[verified]@__kokumotoDisclosure
Sonatype announced that 19 additional packages are affected by the critical CVE‑2026‑29000 in pac4j, but no specific package list, technical details, or mitigation information was provided.
Brut 🇮🇳@wtf_yodhhaPoC
The post announces CVE‑2026‑29000, a critical auth bypass in pac4j‑jwt, and provides a full PoC that exploits it using only a public key, with no hints of active exploitation or a patch.
blueblue@piedpiper1616PoC
The post announces a critical authentication bypass (CVE-2026-29000) in pac4j-jwt, shares a full PoC that leverages only a public key, and links to detailed research.
0xdf@0xdf_PoC
The write‑up details a CVE‑2026‑29000 JWT authentication bypass that allows forging admin tokens with only the public key, password reuse to SSH, and abuse of an SSH CA private key—providing a functional exploitation path but no evidence of active attacks or available patches.