CVE-2026-1195PoC(mineadmin / mineadmin)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mineadmin

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
mineadmin

2 versions affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-26: 1PoC Mentioned / Linked · 2026-03-26: 103-26
Signal classification1 categories
PoC
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • PentesterLab@PentesterLab
    PoC

    Inspired by CVE-2026-1195, make sure you check out our latest lab: JWT: Refresh Token Bypass 🔗 https://pentesterlab.com/exercises/jwt-refresh-bypass

    Post summary

    The tweet promotes a PentesterLab exercise linked to CVE‑2026‑1195, providing a proof‑of‑concept for a JWT refresh token bypass without mentioning active exploitation, patches, or technical details.

    08065385.0K
    201.4K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmineadminmineadmin1.0--
Appmineadminmineadmin2.0--

Explore more