CVE-2026-32295

HIGH

JetKVM insufficient login rate limiting

Title source: cna
STIX 2.1

Description

JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials.

Scores

CVSS v3 7.5
EPSS 0.0004
EPSS Percentile 13.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-307
Status published
Products (3)
JetKVM/JetKVM < 0.5.4
JetKVM/JetKVM 0.5.4
jetkvm/kvm < 0.5.3
Published Mar 17, 2026
Tracked Since Mar 17, 2026