{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-16214", "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "state": "PUBLISHED", "assignerShortName": "VulDB", "dateReserved": "2026-07-18T09:51:40.418Z", "datePublished": "2026-07-19T04:15:09.590Z", "dateUpdated": "2026-07-22T14:59:38.479Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB", "dateUpdated": "2026-07-19T04:15:09.590Z" }, "title": "geex-arts django-jet Dashboard views.py authorization", "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-639", "lang": "en", "description": "Authorization Bypass" } ] }, { "descriptions": [ { "type": "CWE", "cweId": "CWE-285", "lang": "en", "description": "Improper Authorization" } ] } ], "affected": [ { "vendor": "geex-arts", "product": "django-jet", "versions": [ { "version": "1.0.0", "status": "affected" }, { "version": "1.0.1", "status": "affected" }, { "version": "1.0.2", "status": "affected" }, { "version": "1.0.3", "status": "affected" }, { "version": "1.0.4", "status": "affected" }, { "version": "1.0.5", "status": "affected" }, { "version": "1.0.6", "status": "affected" }, { "version": "1.0.7", "status": "affected" }, { "version": "1.0.8", "status": "affected" } ], "cpes": [ "cpe:2.3:a:geex-arts:django-jet:*:*:*:*:*:*:*:*" ], "modules": [ "Dashboard Module" ] } ], "descriptions": [ { "lang": "en", "value": "A vulnerability was identified in geex-arts django-jet up to 1.0.8. This affects an unknown function of the file jet/dashboard/views.py of the component Dashboard Module. Such manipulation leads to authorization bypass. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet." } ], "metrics": [ { "cvssV4_0": { "version": "4.0", "baseScore": 5.3, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P", "baseSeverity": "MEDIUM" } }, { "cvssV3_1": { "version": "3.1", "baseScore": 6.3, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R", "baseSeverity": "MEDIUM" } }, { "cvssV3_0": { "version": "3.0", "baseScore": 6.3, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R", "baseSeverity": "MEDIUM" } }, { "cvssV2_0": { "version": "2.0", "baseScore": 6.5, "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR" } } ], "timeline": [ { "time": "2026-07-18T00:00:00.000Z", "lang": "en", "value": "Advisory disclosed" }, { "time": "2026-07-18T02:00:00.000Z", "lang": "en", "value": "VulDB entry created" }, { "time": "2026-07-18T11:56:59.000Z", "lang": "en", "value": "VulDB entry last update" } ], "credits": [ { "lang": "en", "value": "GalaxynX (VulDB User)", "type": "reporter" }, { "lang": "en", "value": "VulDB CNA Team", "type": "coordinator" } ], "references": [ { "url": "https://vuldb.com/vuln/380037", "name": "VDB-380037 | geex-arts django-jet Dashboard views.py authorization", "tags": [ "vdb-entry" ] }, { "url": "https://vuldb.com/vuln/380037/cti", "name": "VDB-380037 | CTI Indicators (IOB, IOC, IOA)", "tags": [ "signature", "permissions-required" ] }, { "url": "https://vuldb.com/cve/CVE-2026-16214", "name": "CVE-2026-16214 | CVE Analysis and Report", "tags": [ "third-party-advisory" ] }, { "url": "https://vuldb.com/submit/857945", "name": "Submit #857945 | geex-arts django-jet 0cc1e636109f680de6759ac30c0b14ef980883bc CWE-639 Authorization Bypass Through User-Controlled Key", "tags": [ "third-party-advisory" ] }, { "url": "https://github.com/geex-arts/django-jet/issues/528", "tags": [ "exploit", "issue-tracking" ] }, { "url": "https://github.com/geex-arts/django-jet/", "tags": [ "product" ] } ] }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-07-22T14:59:29.316091Z", "id": "CVE-2026-16214", "options": [ { "Exploitation": "poc" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-07-22T14:59:38.479Z" } } ] } }