CVE-2026-16215

Summary

A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the component OAuth Credential Revoke Handler. Performing a manipulation results in missing authorization. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Affected Software

VendorProductVersion RangeStatus
geex-artsdjango-jet1.0.0affected
geex-artsdjango-jet1.0.1affected
geex-artsdjango-jet1.0.2affected
geex-artsdjango-jet1.0.3affected
geex-artsdjango-jet1.0.4affected
geex-artsdjango-jet1.0.5affected
geex-artsdjango-jet1.0.6affected
geex-artsdjango-jet1.0.7affected
geex-artsdjango-jet1.0.8affected

Weaknesses

  • CWE-862: Missing Authorization
  • CWE-863: Incorrect Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: yes
    • Technical Impact: partial

References