Junglewise Threat Intelligence

CVE-2026-75933: Jet Admin JavaScript injection in sign-in page

CVE-2026-75933 · Severity: high · CVSS 7.3 · Published 2026-08-21

Executive brief

Jet Admin is a platform used to build administrative dashboards and applications. An authenticated attacker can inject malicious JavaScript into the sign-in page's customization settings, which then executes in the browser of any user who visits the page, potentially stealing credentials, session tokens, or other sensitive data.

Technical details

This vulnerability is a reflected/stored cross-site scripting (XSS) flaw in Jet Admin's sign-in page customization feature. An authenticated attacker can inject arbitrary JavaScript code via the "scripts and styles" option in the authentication configuration. The injected script executes in the security context of any visiting user's domain, enabling credential theft, session hijacking, or malware distribution. The vulnerability requires prior authentication but does not require user interaction beyond visiting the compromised sign-in page. No patch is currently available.

Affected products

  • Jet Admin Jet Admin all versions

Timeline

  • 2026-08-21: disclosed
  • 2026-08-21: advisory: CISA VA-26-232-02 published; no fix available

References

Related threats