CVE-2026-29000 is a vulnerability tracked across 2 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed March 5, 2026; most recent activity March 6, 2026.
A new CVSS 10.0 vulnerability, CVE-2026-29000, was published on March 4, 2026, allowing attackers to bypass authentication in the pac4j-jwt library, enabling impersonation of any user, including administrators. This…
A vulnerability has been identified in the pac4j-jwt (JwtAuthenticator) module, which could enable attackers to bypass authentication mechanisms. This Java module is part of the pac4j security framework used for…