CVE-2026-32294
Severity CVSS v4.0:
HIGH
Type:
CWE-345
Insufficient Verification of Data Authenticity
Publication date:
17/03/2026
Last modified:
10/04/2026
Description
JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding SHA256 hash to pass verification.
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH
Base Score 3.x
4.70
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:jetkvm:kvm:*:*:*:*:*:*:*:* | 0.5.3 (including) |
To consult the complete list of CPE names with products and versions, see this page



