Medium severity5.0NVD Advisory· Published Jan 20, 2026· Updated Apr 29, 2026
CVE-2026-1195
CVE-2026-1195
Description
A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mineadmin/mineadminPackagist | >= 1.0.0, <= 2.0.3 | — |
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- github.com/SourByte05/MineAdmin-Vulnerability/issues/4nvdExploitIssue TrackingMitigationThird Party AdvisoryWEB
- github.com/advisories/GHSA-43rr-x62x-q96wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-1195ghsaADVISORY
- vuldb.comnvdThird Party AdvisoryVDB EntryWEB
- vuldb.comnvdThird Party AdvisoryVDB EntryWEB
- vuldb.comnvdPermissions RequiredVDB EntryWEB
News mentions
0No linked articles in our index yet.