Certificate Validation Flaw in JumpServer Affecting Multi-Factor Authentication Process
CVE-2026-31798

5MEDIUM

Key Information:

Vendor

Jumpserver

Vendor
CVE Published:
13 March 2026

What is CVE-2026-31798?

JumpServer is an open-source bastion host and operation and maintenance security audit system that faced a significant security issue in its Custom SMS API functionality. Prior to v4.10.16-lts, the application improperly validated certificates, allowing an attacker the capability to intercept MFA/OTP codes sent through the Custom SMS API. This vulnerability could lead to unauthorized access as attackers could capture verification codes before they reached the legitimate user’s device. The issue has been resolved in version 4.10.16-lts, emphasizing the importance of timely software updates to maintain security.

Affected Version(s)

jumpserver < 4.10.16-lts

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.