Security Advisory

CVE-2026-75932

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-21 16:11:24
Last updated 2026-08-21 16:45:46
Assigner cisa-cg
CVSS score 9.2
State PUBLISHED

Description

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client ID and Client Secret if the victim is using an OAuth provider.