Jet Admin allows an authenticated attacker to inject JavaScript via the sign-in page's scripts and styles option. The vulnerability requires authentication and user interaction, potentially impacting users with access to this page. Operators, administrators, and security teams responsible for Jet Admin installations should prioritize patching or mitigating the vulnerability to prevent potential JavaScript [truncated]
Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. The CVE record was published on 2026-08-21T16:18:17.717Z and has not been modified since then. Organizations using Jet Admin should be aware of the critical vulnerability and take immediate action to verify their [truncated]