Executive brief
django-jet, a popular administrative interface template for the Django web framework, contains security flaws in its Dashboard Module. These flaws allow staff members to view or modify dashboard configurations belonging to other users by simply changing a numeric ID in the web address. Additionally, certain features for Google Analytics and Yandex Metrika can be manipulated to disconnect services or link a victim's data to an attacker's dashboard, potentially leading to unauthorized data access or service disruption within the management console.
Technical details
The vulnerability encompasses three distinct authorization issues within the Dashboard Module of django-jet (up to 1.0.8). First, an Insecure Direct Object Reference (IDOR) in `jet/dashboard/views.py` allows any user with 'is_staff' permissions to access or modify dashboard modules of other staff users because the application fails to scope object lookups to the owner. Second, the Google Analytics and Yandex Metrika credential revoke endpoints lack authentication and ownership checks, allowing remote attackers to delete credentials via a simple GET request. Third, the OAuth flow for these modules uses the module's primary key as the 'state' parameter rather than a secure nonce, enabling an attacker to bind a victim's third-party authorization token to an attacker-controlled dashboard module. As of the advisory date, no official patch has been released by the vendor.
Affected products
- geex-arts django-jet up to 1.0.8
Timeline
- 2026-06-13: disclosed: Issue reported to vendor via GitHub issue #528
- 2026-07-19: advisory: CVE-2026-16214 published