Authentication Bypass Vulnerability in Automattic Jetpack Plugin
CVE-2026-106601

5.4MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-106601?

A security flaw in the Automattic Jetpack plugin allows attackers to bypass authentication by exploiting an alternate path or channel, potentially enabling unauthorized users to access sensitive password recovery functions. This vulnerability affects all versions from n/a through 16.2, posing a risk to user data and site integrity.

Affected Version(s)

Jetpack 0 <= 16.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack)
.