A maximum severity vulnerability (CVE-2026-29000) was disclosed in pac4j-jwt's JwtAuthenticator component. The flaw allows a remote unauthenticated attacker who knows the server's RSA public key to bypass authentication and impersonate any user, including admins, by submitting a crafted JWE containing an unsigned PlainJWT
•2m read time• From arcticwolf.com
Table of contents
Upgrade to Latest Fixed ReleaseSort: