Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-75932 | 1 Jet Admin | 1 Jet Admin | 2026-08-21 | 8.6 High |
| Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client ID and Client Secret if the victim is using an OAuth provider. | ||||
| CVE-2026-75933 | 1 Jet Admin | 1 Jet Admin | 2026-08-21 | 7.3 High |
| Jet Admin allows an authenticated attacker to inject JavaScript via the sign-in page's scripts and styles option. Injected script is executed in the context of any visiting user's domain. | ||||
Page 1 of 1.