SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-44845

MEDIUM · CVSS 6.7 EPSS 0.61% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

JumpServer versions prior to 4.10.17 are vulnerable to an injection flaw that allows authenticated administrators with specific permissions to inject Jinja2 expressions into critical fields, leading to the execution of arbitrary commands on the JumpServer control node. This vulnerability poses a medium risk as it could enable unauthorized access and manipulation of the system. Organizations using JumpServer should prioritize upgrading to version 4.10.17 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-44845
Severity
MEDIUM
CVSS
6.7
EPSS
0.61%

Original NVD Description

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an authenticated administrator with Applet Host management and deployment permissions can inject Jinja2 expressions into the IP/Host field or Core Service Address field, causing Ansible to evaluate ansible_host inventory data or playbook variables during Applet Host deployment and execute arbitrary commands on the JumpServer control node. This issue is fixed in version 4.10.17.