A maximum-severity authentication bypass was disclosed in pac4j’s JWT component (pac4j-jwt), tracked as CVE-2026-29000, affecting a widely used Java security engine embedded across many downstream software packages. The issue is a logic flaw that enables attackers to bypass authentication controls by crafting tokens/claims in a way that defeats expected verification, raising concern because exploitation can be relatively straightforward and the library’s transitive use complicates exposure tracking and patch rollout across dependent applications.
Public proof-of-concept (PoC) code is available, and reporting indicates an attacker who can obtain a target server’s RSA public key (often publicly accessible) can forge a JWE-wrapped PlainJWT containing arbitrary sub and role claims to bypass signature verification and authenticate as any user, including administrators. The pac4j maintainer disclosed the defect and released patched versions shortly after private reporting; while there were no confirmed in-the-wild exploits at the time of reporting, defenders should expect downstream vendors and application owners to issue their own advisories and updates as they assess inherited risk from bundled pac4j versions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
F5 issued a product advisory for CVE-2026-29000, indicating the pac4j vulnerability affected or was relevant to F5 products. This marks a downstream vendor response following the earlier pac4j disclosure and patching activity.
CodeAnt AI said it contacted hundreds of maintainers whose repositories may depend on vulnerable pac4j components. Researchers also warned that downstream projects may need to publish their own advisories and patches.
CyberScoop reported that CVE-2026-29000 had been publicly disclosed after CodeAnt AI published a proof-of-concept exploit, warning that the pre-authentication flaw was easy to reproduce with only a server's public RSA key. The report highlighted serious downstream risk because pac4j is embedded in frameworks such as Spring Security, Play Framework, Vert.x, and Javalin.
HKCERT published a security bulletin warning of a pac4j-jwt security restriction bypass vulnerability. The advisory marked broader public disclosure of the issue to defenders and users.
Within two days of the private report, the pac4j maintainer disclosed the vulnerability and issued fixes for affected pac4j versions. The flaw affected the pac4j authentication component used across multiple Java frameworks and downstream projects.
CodeAnt AI discovered a critical logic flaw in pac4j-jwt, later assigned CVE-2026-29000, that could let attackers bypass authentication by forging JWTs or abusing raw JSON claims via JWE. The issue was privately disclosed to the pac4j maintainer before public announcement.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
my.f5.com
Open sourcescworld.com
Open sourcecyberscoop.com
Open sourcehkcert.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.