Feed/CVE-2026-29000
CVE-2026-29000CRITICALCVSS 9.1

CVE-2026-29000

Published Mar 4, 2026·Updated Jul 14, 2026

NVD Description

pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens. Attackers who possess the server's RSA public key can create a JWE-wrapped PlainJWT with arbitrary subject and role claims, bypassing signature verification to authenticate as any user including administrators.

Public Exploits & PoCs17 found

[POC] CVE-2026-29000 — CVE-2026-29000

pac4j-jwt JwtAuthenticator auth bypass (CVE-2026-29000) writeup and PoCs

1

[POC] CVE-2026-29000 — CVE-2026-29000

Python POC, Exploit for CVE-2026-29000

[POC] CVE-2026-29000 — CVE-2026-29000-PoC-Exploit

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets. Keep-alive, proxy, custom JWKS.⚙️ Educational PoC Exploit tool.

[POC] CVE-2026-29000 — CVE-2026-29000

PoC of the CVE-2026-29000

[POC] CVE-2026-29000 — Principal-HackTheBox

Writeup for Principal — HackTheBox Medium Linux box. CVE-2026-29000 pac4j JWT bypass, credentials from API settings, SSH CA privesc to root.

[POC] CVE-2026-29000 — CVE-2026-29000-pac4j-jwt

CVE-2026-29000 PoC: pac4j-jwt PlainJWT-in-JWE authentication bypass.

[POC] CVE-2026-29000 — CVE-2026-29000

An educational deep-dive into CVE-2026-29000

[POC] CVE-2026-29000 — CVE-2026-29000

Proof of Concept for CVE-2026-29000, a vulnerability in pac4j-jwt

[POC] CVE-2026-29000 — CVE-2026-29000-PoC

CVE-2026-29000 - pac4j-jwt (< 4.5.9 / < 5.7.9 / < 6.3.3) JwtAuthenticator authentication bypass PoC

[POC] CVE-2026-29000 — CVE-2026-29000

Just a simple Rust automation for CVE-2026-29000, design to work against ippsec's Principal box on HackTheBox

PoC: pac4j-check

Offline scanner for CVE-2026-29000 (CVSS 10.0) in pac4j-jwt — also finds the 4 packages the official advisory does not list. Single 25KB jar, zero dependencies, Java 8+.

PoC: CVE-2026-29000

CVE-2026-29000: Critical Authentication Bypass in pac4j-jwt - Using Only a Public Key (CVSS 10)

PoC: CVE-2026-29000

CVE-2026-29000

PoC: CVE-2026-29000-pac4j-jwt-auth-bypass

Proof-of-Concept (PoC) for an authentication bypass vulnerability affecting applications using pac4j-jwt with JWE (JSON Web Encryption).

PoC: CVE-2026-29000-pac4j-PoC

Python Proof of Concept (PoC) for CVE-2026-29000: pac4j-jwt Authentication Bypass via Public Key JWE Forgery.

PoC: cve-2026-29000

cve-2026-29000 exploit

PoC: CVE-2026-29000---pac4j-jwt-Authentication-Bypass-PoC

CVE-2026-29000 - pac4j-jwt Authentication Bypass PoC

Community Discussion

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free