Feed/CVE-2026-2900
CVE-2026-2900LOWCVSS 2.7

CVE-2026-2900

Published May 14, 2026·Updated Jun 17, 2026

NVD Description

GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that when instance-level approval rule editing prevention was enabled, could have allowed an authenticated user with Maintainer permissions to modify or delete project approval rules due to missing authorization checks.

Public Exploits & PoCs10 found

[POC] CVE-2026-29000 — CVE-2026-29000

pac4j-jwt JwtAuthenticator auth bypass (CVE-2026-29000) writeup and PoCs

1

[POC] CVE-2026-29000 — CVE-2026-29000

Python POC, Exploit for CVE-2026-29000

[POC] CVE-2026-29000 — CVE-2026-29000-PoC-Exploit

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets. Keep-alive, proxy, custom JWKS.⚙️ Educational PoC Exploit tool.

[POC] CVE-2026-29000 — CVE-2026-29000

PoC of the CVE-2026-29000

[POC] CVE-2026-29000 — Principal-HackTheBox

Writeup for Principal — HackTheBox Medium Linux box. CVE-2026-29000 pac4j JWT bypass, credentials from API settings, SSH CA privesc to root.

[POC] CVE-2026-29000 — CVE-2026-29000-pac4j-jwt

CVE-2026-29000 PoC: pac4j-jwt PlainJWT-in-JWE authentication bypass.

[POC] CVE-2026-29000 — CVE-2026-29000

An educational deep-dive into CVE-2026-29000

[POC] CVE-2026-29000 — CVE-2026-29000

Proof of Concept for CVE-2026-29000, a vulnerability in pac4j-jwt

[POC] CVE-2026-29000 — CVE-2026-29000-PoC

CVE-2026-29000 - pac4j-jwt (< 4.5.9 / < 5.7.9 / < 6.3.3) JwtAuthenticator authentication bypass PoC

[POC] CVE-2026-29000 — CVE-2026-29000

Just a simple Rust automation for CVE-2026-29000, design to work against ippsec's Principal box on HackTheBox

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free