News

JumpServer v4.10.14-lts Release Notes

#Release Notes
JumpServer v4.10.14-lts Release Notes

What’s new

  • JumpServer Client now supports OAuth 2.0 authentication, improving client login compatibility.

  • User operation audit logs can now be exported as CSV / Excel files for easier auditing and record keeping.

  • Cloud synchronization now supports State Cloud. (JumpServer EE)

  • Virtual applications can now be accessed via the VNC protocol using the local client. (JumpServer EE)

Improvements

  • Intelligent Q&A now supports user-defined models, enabling flexible AI interactions across different scenarios.

  • Kubernetes platform protocol now supports namespace configuration, restricting user access to authorized namespaces only for improved access control.

Bug fixes

  • Fixed a memory leak issue in Razor components. (JumpServer EE)

  • Fixed an issue where filtering commands by risk level returned empty results.

  • Fixed an issue where shared session links could not be copied after connecting via different endpoints.

Keep Reading

Recommended Reading

Important Notice: JumpServer Vulnerability Advisory and Remediation (JS-2026.09.09)
Security

Important Notice: JumpServer Vulnerability Advisory and Remediation (JS-2026.09.09)

JumpServer security advisory JS-2026.09.09: an improper API filtering vulnerability (GHSA-6rp5-ff2m-qfrm, High, CVSS 8.8) lets any authenticated user retrieve administrator Access Keys by appending a query parameter. Affects V3 >= v3.7.0 and < v3.10.23 LTS, and V4 >= v4.0.0 and < v4.10.19 LTS. Upgrade or apply the Nginx workaround immediately.

Download Community Free Trial