Retour à la veille

CVE-2026-75932

Publié : 21 août 2026
Modifié : 21 août 2026
Lien officiel NVD
Score CVSS
8.6
HIGH

Description détaillée

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client ID and Client Secret if the victim is using an OAuth provider.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Références et Patchs