Arbitrary Command Execution Vulnerability in JumpServer Open Source Bastion Host
CVE-2026-44845

6.7MEDIUM

Key Information:

Vendor

Jumpserver

Vendor
CVE Published:
17 August 2026

What is CVE-2026-44845?

JumpServer, an open source bastion host and security audit system, has a vulnerability that allows authenticated administrators with the appropriate management permissions to inject Jinja2 expressions into critical fields such as the IP/Host or Core Service Address. This injection can lead to the evaluation of sensitive Ansible inventory data or playbook variables, potentially allowing unauthorized command execution on the JumpServer control node. This vulnerability has been addressed in version 4.10.17.

Affected Version(s)

jumpserver < 4.10.17

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.