PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-49075 Jetimpex Inc. CVE debrief

A critical PHP object injection vulnerability was discovered in JetEngine plugin version 3.8.9.1 and earlier. This vulnerability has a CVSS score of 9.8 and can allow an attacker to execute arbitrary code on the affected system. The vulnerability was publicly disclosed on June 17, 2026. Users of the affected plugin should update to the latest version as soon as possible. The vulnerability is tracked under CVE-2026-49075. [ref-4] provides additional information on the vulnerability and potential mitigations.

Vendor
Jetimpex Inc.
Product
JetEngine
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-17
Original CVE updated
2026-06-17
Advisory published
2026-06-17
Advisory updated
2026-06-17

Who should care

Administrators and users of the JetEngine plugin version 3.8.9.1 and earlier should be aware of this critical vulnerability. Updating to the latest version of the plugin is highly recommended to prevent potential exploitation.

Technical summary

The CVE-2026-49075 vulnerability is a PHP object injection issue in the JetEngine plugin. It has been assigned a CVSS score of 9.8, indicating critical severity. The vulnerability allows for unauthenticated attacks with high impact on confidentiality, integrity, and availability. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The weakness is categorized under CWE-502.

Defensive priority

high

Recommended defensive actions

  • Update the JetEngine plugin to the latest version.
  • Review and monitor the system for potential suspicious activity.
  • Implement additional security measures such as web application firewalls.
  • Restrict access to the plugin and system.
  • Regularly update and patch all plugins and software.
  • Consider implementing a vulnerability management program.
  • Monitor for indicators of compromise.

Evidence notes

The information provided is based on data from [nvd] and [ref-4]. The CVE record and NVD detail can be found at [cve-org] and [nvd], respectively. Additional information and potential mitigations can be found at [ref-4].

Sources and references

Verified primary and authoritative sources

  • CVE-2026-49075 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-49075

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-49075 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49075

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.