Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-75932— Jet Admin tenant isolation failure

Quick assessment

Affected
Jet Admin Jet Admin
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Jet Admin 允许攻击者创建一个恶意应用,并将其连接到目标用户的自定义域名。攻击者可以篡改认证配置,将流量重定向至由其控制的恶意应用。一旦该恶意应用与目标域名成功关联,若目标用户使用了 OAuth 提供商,则攻击者的工作区将自动获取受害者的 OAuth 客户端 ID 和客户端密钥。

CVSS 8.6 · High EPSS 0.40% · P33

Affected Version Matrix 1

VendorProduct Version RangeStatus
Jet Admin Jet Admin < * affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-75932

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Jet Admin tenant isolation failure
Source: CVE Program / CVE List V5
Vulnerability Description
Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client ID and Client Secret if the victim is using an OAuth provider.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Jet Admin Jet Admin 0 ~ * -

II. Public POCs for CVE-2026-75932

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-75932

登录查看更多情报信息。

Vendor Advisories for CVE-2026-75932 (1)

News Coverage for CVE-2026-75932 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-75932

No comments yet


Leave a comment