CVE-2026-32295
CVE-2026-32295
9.3
CriticalPublished:
Last updated:
Source:9119a7d8-5eab-497f-8521-727c672e3725
Analyzed
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- None
- User Interaction
- None
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- None
- Availability (Vulnerable)
- None
- Confidentiality (Subsequent)
- High
- Integrity (Subsequent)
- High
- Availability (Subsequent)
- High
Description
JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials.
References
9119a7d8-5eab-497f-8521-727c672e3725
https://eclypsium.com/blog/kvm-devices-the-keys-to-your-kingdom-are-hanging-on-the-network/9119a7d8-5eab-497f-8521-727c672e3725
https://github.com/jetkvm/kvm/releases/tag/release%2F0.5.49119a7d8-5eab-497f-8521-727c672e3725
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-076-01.json9119a7d8-5eab-497f-8521-727c672e3725
https://www.cve.org/CVERecord?id=CVE-2026-32295