Vulnerability in Jet Admin Affects Custom Domain Authentication Configuration
CVE-2026-75932

9.2CRITICAL

Key Information:

Vendor

Jet Admin

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-75932?

A security flaw in Jet Admin enables attackers to craft malicious applications that can be connected to a victim's custom domain. This allows them to manipulate the authentication configuration, leading to traffic rerouting to a compromised application. When the victim utilizes an OAuth provider, the attacker's workspace can be populated with sensitive OAuth credentials, such as Client ID and Client Secret, creating significant security risks for affected users.

Affected Version(s)

Jet Admin 0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mahmoud Elkhaligy
.