Privilege Escalation in JumpServer Open Source Bastion Host
CVE-2026-44846
6.2MEDIUM
What is CVE-2026-44846?
JumpServer, an open-source bastion host and security audit system, is affected by a vulnerability that allows users with the 'users.invite_user' permission to manipulate the organization invitation logic. This can lead to unauthorized privilege escalation or the potential downgrading of administrator roles by replacing existing organization roles. The issue has been addressed in version 4.10.17, emphasizing the need for users to update their installations to maintain security.
Affected Version(s)
jumpserver < 4.10.17
