Authentication Bypass Vulnerability in Automattic Jetpack
CVE-2026-106602

4.8MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-106602?

An authentication bypass vulnerability exists in Automattic's Jetpack that allows attackers to exploit the password recovery feature. This flaw enables unauthorized access by circumventing intended authentication mechanisms, potentially leading to unauthorized actions within the affected Jetpack versions. This issue impacts users from version n/a through 16.2, necessitating immediate attention to safeguard against potential exploits.

Affected Version(s)

Jetpack 0 <= 16.2

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack)
.