logo

Critical pac4j-jwt Authentication Bypass Vulnerability Allows Attackers to Impersonate Any User

ID: 368c38f5-b4b6-5a29-873e-29bfa7564291

STIX ID: report--368c38f5-b4b6-5a29-873e-29bfa7564291

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-05

Date Updated: 2026-04-22

Author: Divya

...
...

A critical authentication bypass (CVE-2026-29000, CVSS 10.0) in the pac4j-jwt Java library permits attackers to craft a PlainJWT encrypted with the server's public RSA key that is improperly parsed and causes signature verification to be skipped, enabling full user impersonation including administrators; maintainers have released patches (upgrade to 4.5.9+, 5.7.9+, or 6.3.3+) and immediate dependency updates are advised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.