Privilege Escalation in JumpServer Open Source Bastion Host
CVE-2026-44846

6.2MEDIUM

Key Information:

Vendor

Jumpserver

Vendor
CVE Published:
17 August 2026

What is CVE-2026-44846?

JumpServer, an open-source bastion host and security audit system, is affected by a vulnerability that allows users with the 'users.invite_user' permission to manipulate the organization invitation logic. This can lead to unauthorized privilege escalation or the potential downgrading of administrator roles by replacing existing organization roles. The issue has been addressed in version 4.10.17, emphasizing the need for users to update their installations to maintain security.

Affected Version(s)

jumpserver < 4.10.17

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.