A maximum severity vulnerability (CVE-2026-29000) was disclosed in pac4j-jwt's JwtAuthenticator component. The flaw allows a remote unauthenticated attacker who knows the server's RSA public key to bypass authentication and impersonate any user, including admins, by submitting a crafted JWE containing an unsigned PlainJWT

2m read time From arcticwolf.com
Post cover image
Table of contents
Upgrade to Latest Fixed Release

Sort: