Arbitrary Command Execution Vulnerability in JumpServer Open Source Bastion Host
CVE-2026-44845
6.7MEDIUM
What is CVE-2026-44845?
JumpServer, an open source bastion host and security audit system, has a vulnerability that allows authenticated administrators with the appropriate management permissions to inject Jinja2 expressions into critical fields such as the IP/Host or Core Service Address. This injection can lead to the evaluation of sensitive Ansible inventory data or playbook variables, potentially allowing unauthorized command execution on the JumpServer control node. This vulnerability has been addressed in version 4.10.17.
Affected Version(s)
jumpserver < 4.10.17
