Junglewise Threat Intelligence

CVE-2026-75932: Jet Admin tenant isolation failure

CVE-2026-75932 · Severity: high · CVSS 8.6 · Published 2026-08-21

Executive brief

Jet Admin is a low-code platform for building business applications and admin panels. An attacker can exploit missing authorization controls to create a malicious app connected to a target user's custom domain, reconfigure authentication settings, and intercept traffic. If the target uses OAuth, the attacker gains access to the victim's OAuth credentials, enabling account takeover and data theft.

Technical details

The vulnerability is a missing authorization (CWE-862) and tenant isolation failure in Jet Admin's app management and domain binding logic. An unauthenticated or authenticated attacker can create a malicious app, bind it to a victim's custom domain, modify authentication configuration, and redirect legitimate traffic to an attacker-controlled application. When the victim's domain uses OAuth, the attacker's workspace is automatically populated with the victim's OAuth Client ID and Client Secret. The attacker can then inject malicious JavaScript via the sign-in page configuration, which executes in the context of any user accessing that domain. Network attack vector, no special preconditions. No fix is currently available.

Affected products

  • Jet Admin Jet Admin all versions

Timeline

  • 2026-08-21: disclosed
  • 2026-08-21: advisory: CISA VA-26-232-02

References

Related threats