CVE-2026-29000
pac4j-jwt Authentication Bypass via Encrypted JWT Forgery
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A critical authentication bypass vulnerability exists in pac4j-jwt when processing encrypted JWTs, allowing remote attackers to forge tokens and impersonate users, including administrators. This occurs if an attacker possesses the server's RSA public key and can craft a malicious token that bypasses signature verificat