CVE-2026-75932

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client ID and Client Secret if the victim is using an OAuth provider.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-21 16:18

Updated : 2026-08-26 16:52


NVD link : CVE-2026-75932

Mitre link : CVE-2026-75932

CVE.ORG link : CVE-2026-75932


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization