CVE-2026-29000 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
March 5, 2026
Last Seen
March 6, 2026

CVE-2026-29000 is a vulnerability tracked across 2 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed March 5, 2026; most recent activity March 6, 2026.

Related Threat Clusters

  • New CVSS 10.0 Vulnerability CVE-2026-29000 Discovered

    A new CVSS 10.0 vulnerability, CVE-2026-29000, was published on March 4, 2026, allowing attackers to bypass authentication in the pac4j-jwt library, enabling impersonation of any user, including administrators. This…

    2 articles · Updated March 6, 2026
  • Vulnerability in pac4j-jwt Allows for Potential Authentication Bypass

    A vulnerability has been identified in the pac4j-jwt (JwtAuthenticator) module, which could enable attackers to bypass authentication mechanisms. This Java module is part of the pac4j security framework used for…

    10 articles · Updated March 5, 2026

Recent Intelligence Reports

  • Why CVSS 10 Vulnerabilities Are So Dangerous (Real Examples) — Codeant.Ai · March 6, 2026
  • Amartya Jha's Post — Linkedin · March 6, 2026
  • CVSS 10.0 auth bypass in pac4j-jwt - anyone here running pac4j in their stack? : r/sysadmin — Reddit · March 5, 2026
  • With CVE-2026-29000, what are the most notable CVSS 10.0 vulnerabilities of all time? — Reddit · March 5, 2026
  • PSA: If you use pac4j for JWT authentication, you need to patch immediately, CVSS 10.0 auth bypass — Reddit · March 5, 2026

CVSS v3.1 Breakdown