CVE-2026-32295 impacts JetKVM versions before 0.5.4 due to a critical lack of rate limiting on login requests, enabling unauthenticated attackers to perform brute-force credential guessing. Rated 7.5 High on the CVSS scale, this vulnerability is easily exploitable over the network with low complexity, leading to a high confidentiality impact through unauthorized access. While no public exploits are currently available in common databases and it is not in CISA's KEV catalog, it is listed as "Active" on the Hot List and has generated some community discussion, indicating potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.5.3CPE matchmatch criteria | cpe:2.3:a:jetkvm:kvm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.