Description
A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the component OAuth Credential Revoke Handler. Performing a manipulation results in missing authorization. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-07-19
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the OAuth Credential Revoke Handler of geex‑arts django‑jet versions up to 1.0.8 enables an attacker to manipulate requests and cause missing authorization checks, which can result in unauthorized revocation of OAuth credentials. This breach falls under missing or insufficient authorization weaknesses (CWE‑862 and CWE‑863) and undermines the integrity of the authentication and authorization process. The impact is that an attacker could revoke valid OAuth tokens without proper authentication, potentially preventing legitimate users from accessing protected resources or allowing an attacker to further exploit the revoked credentials for other attacks.

Affected Systems

The vulnerability affects geex‑arts django‑jet up to and including version 1.0.8. The component involved is the OAuth Credential Revoke Handler within the Django‑jet package. No other releases are listed as affected.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. The EPSS score is less than 1 %, implying a low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, yet the exploit is publicly available and can be performed remotely by sending crafted requests to the revocation endpoint. It is inferred that authentication is not required to trigger the missing authorization, which makes the attack vector readily exploitable if the endpoint remains exposed.

Generated by OpenCVE AI on July 30, 2026 at 22:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest geex‑arts django‑jet release (post‑1.0.8) to apply the vendor fix
  • Configure the OAuth revoke endpoint to require authenticated and authorized access only, restricting it to trusted administrative users
  • Enable detailed logging and alerting for revocation attempts to detect and mitigate potential abuse

Generated by OpenCVE AI on July 30, 2026 at 22:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 19 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the component OAuth Credential Revoke Handler. Performing a manipulation results in missing authorization. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Title geex-arts django-jet OAuth Credential Revoke authorization
First Time appeared Geex-arts
Geex-arts django-jet
Weaknesses CWE-862
CWE-863
CPEs cpe:2.3:a:geex-arts:django-jet:*:*:*:*:*:*:*:*
Vendors & Products Geex-arts
Geex-arts django-jet
References
Metrics cvssV2_0

{'score': 6.4, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Geex-arts Django-jet
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-20T10:33:32.993Z

Reserved: 2026-07-18T09:51:48.373Z

Link: CVE-2026-16215

cve-icon Vulnrichment

Updated: 2026-07-20T10:33:28.950Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T22:45:04Z

Weaknesses