PT-2026-94119 · Djust · Djust

CVE-2026-61591

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions djust versions prior to 1.0.7
Description For views that utilize state snapshots, the state json snapshot embedded in the client page is restored upon reconnection as trusted view state without an integrity check. This allows a client to modify the unsigned state json and return it in the reconnect mount frame to inject arbitrary view attributes. Examples of exploitation include changing is admin to True or altering account id and balance, leading to privilege escalation or tampering with business state stored in public view attributes.
Recommendations Update to version 1.0.7. As a temporary workaround, disable state snapshots and avoid storing authorization or ownership state in public view attributes.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61591
GHSA-C67V-VQRP-M5WJ

Affected Products

Djust