SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-75932

HIGH · CVSS 8.6 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Jet Admin is vulnerable to exploitation, allowing attackers to create malicious applications that can connect to a target user's custom domain. This can lead to unauthorized access to sensitive OAuth credentials, enabling the attacker to manipulate authentication configurations and reroute traffic. Organizations utilizing Jet Admin, particularly those leveraging OAuth for authentication, should prioritize addressing this vulnerability to protect their users' data and prevent potential breaches.

CVE
CVE-2026-75932
Severity
HIGH
CVSS
8.6
EPSS
0.40%

Original NVD Description

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client ID and Client Secret if the victim is using an OAuth provider.