This article addresses customer concerns regarding CVE‑2026‑29000, a reported vulnerability in pac4j‑jwt involving the JwtAuthenticator component, which could potentially allow authentication bypass in applications using that library.
After internal review and consultation with SAS engineering, Safeguard Authentication Services (SAS) has been confirmed not affected by this vulnerability.
SAS does not utilize pac4j, pac4j‑jwt, or the JwtAuthenticator component in any capacity.
Therefore:
This determination has been validated by One Identity engineering (R&D).
© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center