logo

Critical defect in Java security engine poses serious downstream security risks

ID: 71efbf6f-60f9-5ce5-9589-87faad368a77

STIX ID: report--71efbf6f-60f9-5ce5-9589-87faad368a77

Feed Name: CyberScoop

Threat Score
80/100

Date Published: 2026-03-10

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

A maximum-severity vulnerability (CVE-2026-29000) in the pac4j Java authentication engine enables authentication bypass via forged JWTs or raw JWE claims; a public proof-of-concept was published and patches have been issued. The flaw impacts many downstream frameworks (Spring Security, Play, Vert.x, Javalin, etc.), requires only access to a server's public RSA key, and poses widespread risk until downstream consumers apply fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.