CVE-2026-16216

Summary

A weakness has been identified in geex-arts django-jet up to 1.0.8. Affected is an unknown function of the component OAuth Handler. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Affected Software

VendorProductVersion RangeStatus
geex-artsdjango-jet1.0.0affected
geex-artsdjango-jet1.0.1affected
geex-artsdjango-jet1.0.2affected
geex-artsdjango-jet1.0.3affected
geex-artsdjango-jet1.0.4affected
geex-artsdjango-jet1.0.5affected
geex-artsdjango-jet1.0.6affected
geex-artsdjango-jet1.0.7affected
geex-artsdjango-jet1.0.8affected

Weaknesses

  • CWE-352: Cross-Site Request Forgery
  • CWE-862: Missing Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

References