vulns.co
/
GKData.io MCP

CodeAnt AI · 1 min read

pac4j JWT validation: confidentiality does not establish authenticity

Research on CVE-2026-29000 describes an authentication boundary failure: successful decryption could allow claims to become an authenticated profile without mandatory signature validation. The researcher reports arbitrary identity and role acceptance in a library-level demonstration on 6.0.3; production compromise is not established.

Open the reference Research PaperReviewed 2026-10-03

How to use this reference

Treat authenticity checks as mandatory, fail-closed prerequisites for profile creation. Review all accepted token representations. The maintainer confirms remediation and directs upgrades to 4.5.9, 5.7.9 or 6.3.3 and newer within those release lines.

Before reading

  • Basic authentication and access-control concepts
  • Familiarity with application trust boundaries

Context and limits

  • The demonstrated configuration uses RSA-encrypted JWTs with signature and encryption configuration; exposure cannot be inferred from any pac4j dependency alone.
  • Application-specific consequences depend on how authenticated claims map to authorization.
  • The maintainer confirms the issue and research credit but withholds technical details; the detailed mechanism remains researcher evidence.
  • Article publication is separate from reporting and patch events. The article describes February 28 private disclosure and patches by March 2, 2026; exact version-release dates are not recorded here.

Sources and provenance

  1. CVE-2026-29000: pac4j-jwt Auth Bypass PoC With a Public Key CodeAnt AI · reviewed 2026-10-03
  2. Security advisory for pac4j-jwt (JwtAuthenticator) pac4j · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software