jumpserver Latest Vulnerabilities
Latest vulnerabilities published by jumpserver
Vulnerability Published:
ποΈ Published
- Anytime
Sort By:
ποΈ Published Date
- Descending
Privilege Escalation in JumpServer Open Source Bastion Host
CVE-2026-44846JumpserverJumpserver6.2MEDIUMArbitrary Command Execution Vulnerability in JumpServer Open Source Bastion Host
CVE-2026-44845JumpserverJumpserver6.7MEDIUMSFTP Path Traversal Vulnerability in JumpServer by Jumpserver
CVE-2026-54336JumpserverJumpserver5.4MEDIUMServer-Side Template Injection in JumpServer by JumpServer
CVE-2026-31864JumpserverJumpserver6.8MEDIUMCertificate Validation Flaw in JumpServer Affecting Multi-Factor Authentication Process
CVE-2026-31798JumpserverJumpserver5MEDIUMOpen Redirect Vulnerability in JumpServer Bastion Host by JumpServer
CVE-2025-58044JumpserverJumpserver5.5MEDIUMUnauthorized Access in JumpServer Bastion Host by Low-Privileged Users
CVE-2025-62795JumpserverJumpserver7.1HIGHUnauthorized Access Vulnerability in JumpServer by JumpServer
CVE-2025-62712JumpserverJumpserver9.6CRITICALVulnerability in JumpServer's Kubernetes Session Feature Allows Unauthorized Access
CVE-2025-27095JumpserverJumpserver4.3MEDIUMSecrets Disclosure Vulnerability in JumpServer PAM Tool
CVE-2024-40628JumpserverJumpserver9.1CRITICALAnsible Playbook Exploit Allows Remote Code Execution in Celery Container
CVE-2024-40629JumpserverJumpserver9.8CRITICALJinja2 Template Injection Vulnerability Affects JumpServer's Ansible
CVE-2024-29202JumpserverJumpserverπ°9.9CRITICALArbitrary Code Execution Vulnerability in JumpServer's Ansible Could Lead to Sensitive Information Theft or Database Manipulation
CVE-2024-29201JumpserverJumpserverπΎπ‘π°9.9CRITICALSensitive Information Disclosure Vulnerability in JumpServer
CVE-2024-29020JumpserverJumpserver5.3MEDIUMJumpServer Bastion Host Vulnerable to IDOR Attacks
CVE-2024-29024JumpserverJumpserver5.3MEDIUMJumpServer vulnerability affects phishing and cross-site scripting attacks
CVE-2024-24763jumpserverjumpserver6.1MEDIUMJumpServer default admin user email leak password reset
CVE-2023-46138JumpserverJumpserver3.7LOWjumpserver is vulnerable to password brute-force protection bypass via arbitrary IP values
CVE-2023-46123JumpserverJumpserver5.3MEDIUMSSH public key login without private key challenge if mfa is enabled in jumpserver
CVE-2023-42818JumpserverJumpserver9.8CRITICALRemote code execution on the host system via MongoDB shell in jumpserver
CVE-2023-43651JumpserverJumpserver9.9CRITICALNon-MFA account takeover via brute-force attack on weak password reset code in jumpserver
CVE-2023-43650JumpserverJumpserver7.4HIGHNon-MFA account takeover via using only SSH public key to login in jumpserver
CVE-2023-43652JumpserverJumpserver9.1CRITICALPath traversal in Jumpserver
CVE-2023-42819JumpserverJumpserverπΎπ‘8.9HIGHRandom seed leakage in Jumpserver
CVE-2023-42820JumpserverJumpserverπΎπ‘7HIGHJumpServer session replays download without authentication
CVE-2023-42442jumpserverjumpserverπΎπ‘EPSS 55%5.3MEDIUM