CVE-2026-16214

Summary

A vulnerability was identified in geex-arts django-jet up to 1.0.8. This affects an unknown function of the file jet/dashboard/views.py of the component Dashboard Module. Such manipulation leads to authorization bypass. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected Software

VendorProductVersion RangeStatus
geex-artsdjango-jet1.0.0affected
geex-artsdjango-jet1.0.1affected
geex-artsdjango-jet1.0.2affected
geex-artsdjango-jet1.0.3affected
geex-artsdjango-jet1.0.4affected
geex-artsdjango-jet1.0.5affected
geex-artsdjango-jet1.0.6affected
geex-artsdjango-jet1.0.7affected
geex-artsdjango-jet1.0.8affected

Weaknesses

  • CWE-639: Authorization Bypass
  • CWE-285: Improper Authorization

References