CVE-2026-29000
Description
pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens. Attackers who possess the servers RSA public key can create a JWE-wrapped PlainJWT with arbitrary subject and role claims, bypassing signature verification to authenticate as any user including administrators.
Risk Information
Base Score
9.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
0.057
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2026-29000 are fixed in Pac4j - pac4j-jwt 6.3.3 | Windows |
| Vulnerabilities CVE-2026-29000 are fixed in Pac4j - pac4j-jwt 5.7.9 | Windows |
| Vulnerabilities CVE-2026-29000 are fixed in Pac4j - pac4j-jwt 4.5.9 | Windows |
| Vulnerabilities CVE-2026-29000 are fixed in Pac4j - pac4j-jwt for Linux 6.3.3 | Linux |
| Vulnerabilities CVE-2026-29000 are fixed in Pac4j - pac4j-jwt for Linux 5.7.9 | Linux |
| Vulnerabilities CVE-2026-29000 are fixed in Pac4j - pac4j-jwt for Linux 4.5.9 | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234