Critical 10.0 CVSS Flaw in pac4j-jwt Lets Hackers Forge Admin Tokens
ID: db285201-12c7-5411-a981-ced1426555e5
STIX ID: report--db285201-12c7-5411-a981-ced1426555e5
Feed Name: securityonline.info
Threat Score
Critical vulnerability CVE-2026-29000 in the pac4j-jwt library allows an attacker who possesses the server's RSA public key to craft a JWE-wrapped unsigned JWT that bypasses signature verification in JwtAuthenticator, enabling impersonation of any user (including administrators) and potential full system compromise; the maintainer has confirmed the issue and released patches, so immediate updates are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
