CVE-2026-75933: Jet Admin Stored XSS
Published Aug 21, 2026
·Updated
Jet Admin allows an authenticated attacker to inject JavaScript via the sign-in page's scripts and styles option. Injected script is executed in the context of any visiting user's domain.
Event History
Aug 21, 2026
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access and user interaction are required for exploitation?
An attacker must be authenticated and able to inject JavaScript through the sign-in page’s scripts and styles option. A user must then visit the affected page for the injected script to execute in that user’s domain context.
2
What could an attacker achieve after successful exploitation?
The injected JavaScript executes in the context of visiting users’ domains. The supplied severity vector indicates high confidentiality and integrity impact, with no availability impact.