CVE-2026-29000 Details
Description
pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens. Attackers who possess the server's RSA public key can create a JWE-wrapped PlainJWT with arbitrary subject and role claims, bypassing signature verification to authenticate as any user including administrators.
An authentication bypass vulnerability has been identified in the pac4j-jwt library, specifically in versions prior to 4.5.9, 5.7.9, and 6.3.3. This vulnerability arises in the JwtAuthenticator component when handling encrypted JSON Web Tokens (JWTs). It allows remote attackers to forge authentication tokens by creating a JWE-wrapped PlainJWT with arbitrary subject and role claims. Attackers must possess the server's RSA public key to exploit this vulnerability, as it bypasses signature verification, enabling authentication as any user, including administrators.
Users of pac4j-jwt should upgrade to version 4.5.9 or newer for the 4.x line, version 5.7.9 or newer for the 5.x line, and version 6.3.3 or newer for the 6.x line.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 4, 2026CISA-ADP
Assessed Mar 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-347 | Improper Verification of Cryptographic Signature | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| pac4j-jwt | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 10, 2026 | CVE Modified | [email protected] |
| Mar 4, 2026 | New CVE Received | [email protected] |
Volerion