CVE-2026-75932
Last modified
CVE-2026-75932 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client ID and Client Secret if the victim is using an OAuth provider.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client ID and Client Secret if the victim is using an OAuth provider.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Jet Admin | Jet Admin | < * |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-75932?
How severe is CVE-2026-75932?
How do I fix CVE-2026-75932?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-75926Hugo 0.161.0 placed the Node asset pipelines behind the Node…8.6
- CVE-2026-75927The PublishPress Capabilities – User Role Editor, Access Per…7.2
- CVE-2026-75928The Brushfire platform's video content streaming application…5.3
- CVE-2026-7593A security vulnerability has been detected in Sunwood-ai-lab…7.3
- CVE-2026-75930The FundEngine – Donation and Crowdfunding Platform plugin f…4.3
- CVE-2026-75931fast-uri is a URI parser for Node.js. It canonicalizes a hos…7.5
- CVE-2026-75933Jet Admin allows an authenticated attacker to inject JavaScr…7.3
- CVE-2026-75935Uncontrolled memory allocation in the binary Ion stream curs…7.5
- CVE-2026-75936Improper handling of highly compressed data in the GZIP auto…7.5
- CVE-2026-7594A vulnerability was detected in Flux159 mcp-game-asset-gen 0…7.3
- CVE-2026-75940A vulnerability was reported in Lenovo Health Android Applic…9.1
- CVE-2026-75946A potential security vulnerability has been identified in th…8.2
Are you affected by CVE-2026-75932?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
