Certificate Validation Flaw in JumpServer Affecting Multi-Factor Authentication Process
CVE-2026-31798
5MEDIUM
What is CVE-2026-31798?
JumpServer is an open-source bastion host and operation and maintenance security audit system that faced a significant security issue in its Custom SMS API functionality. Prior to v4.10.16-lts, the application improperly validated certificates, allowing an attacker the capability to intercept MFA/OTP codes sent through the Custom SMS API. This vulnerability could lead to unauthorized access as attackers could capture verification codes before they reached the legitimate user’s device. The issue has been resolved in version 4.10.16-lts, emphasizing the importance of timely software updates to maintain security.
Affected Version(s)
jumpserver < 4.10.16-lts
