CVE-2026-75932
Received Received - Intake

Malicious App Rerouting in Jet Admin

Vulnerability report for CVE-2026-75932, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-21

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client ID and Client Secret if the victim is using an OAuth provider.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-21
Generated
2026-08-21
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jet_admin jet_admin *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Jet Admin vulnerability allows an attacker to create a malicious app and connect it to a victim's custom domain. The attacker can then edit authentication settings and redirect traffic to their own app. If the victim uses an OAuth provider, the attacker's workspace may receive the victim's OAuth Client ID and Client Secret.

Impact Analysis

An attacker could gain unauthorized access to sensitive data, impersonate legitimate users, or intercept communications. This could lead to data breaches, financial loss, or reputational damage depending on the compromised system.

Compliance Impact

This vulnerability could lead to unauthorized data access or exposure, violating GDPR's data protection requirements or HIPAA's safeguards for protected health information. Organizations may face legal penalties, fines, or loss of compliance certifications.

Mitigation Strategies

Review and restrict Jet Admin app connections to your custom domains. Audit authentication configurations for unauthorized changes. Monitor for suspicious OAuth client ID and secret usage in attacker-controlled apps.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75932. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart