Server-Side Template Injection in JumpServer by JumpServer
CVE-2026-31864

6.8MEDIUM

Key Information:

Vendor

Jumpserver

Vendor
CVE Published:
13 March 2026

What is CVE-2026-31864?

JumpServer, an open-source bastion host and operation maintenance security audit system, has a security flaw in its Applet and VirtualApp upload functionalities. This issue allows users with administrative privileges to exploit the application through a Server-Side Template Injection (SSTI). The flaw originates from the insecure use of Jinja2 template rendering when handling user-uploaded YAML configuration files. When an Applet or VirtualApp ZIP package is uploaded, the manifest.yml file undergoes rendering without necessary sandbox restrictions, making it vulnerable to template injection attacks that can lead to arbitrary code execution within the JumpServer Core container.

Affected Version(s)

jumpserver < 3.10.22 < 3.10.22

jumpserver >= 4.0.0, < 4.10.16 < 4.0.0, 4.10.16

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.