GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that when instance-level approval rule editing prevention was enabled, could have allowed an authenticated user with Maintainer permissions to modify or delete project approval rules due to missing authorization checks.
[POC] CVE-2026-29000 — CVE-2026-29000
pac4j-jwt JwtAuthenticator auth bypass (CVE-2026-29000) writeup and PoCs
[POC] CVE-2026-29000 — CVE-2026-29000
Python POC, Exploit for CVE-2026-29000
[POC] CVE-2026-29000 — CVE-2026-29000-PoC-Exploit
CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets. Keep-alive, proxy, custom JWKS.⚙️ Educational PoC Exploit tool.
[POC] CVE-2026-29000 — CVE-2026-29000
PoC of the CVE-2026-29000
[POC] CVE-2026-29000 — Principal-HackTheBox
Writeup for Principal — HackTheBox Medium Linux box. CVE-2026-29000 pac4j JWT bypass, credentials from API settings, SSH CA privesc to root.
[POC] CVE-2026-29000 — CVE-2026-29000-pac4j-jwt
CVE-2026-29000 PoC: pac4j-jwt PlainJWT-in-JWE authentication bypass.
[POC] CVE-2026-29000 — CVE-2026-29000
An educational deep-dive into CVE-2026-29000
[POC] CVE-2026-29000 — CVE-2026-29000
Proof of Concept for CVE-2026-29000, a vulnerability in pac4j-jwt
[POC] CVE-2026-29000 — CVE-2026-29000-PoC
CVE-2026-29000 - pac4j-jwt (< 4.5.9 / < 5.7.9 / < 6.3.3) JwtAuthenticator authentication bypass PoC
[POC] CVE-2026-29000 — CVE-2026-29000
Just a simple Rust automation for CVE-2026-29000, design to work against ippsec's Principal box on HackTheBox
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free