Security

Important Notice: JumpServer Vulnerability Advisory and Remediation (JS-2026.7.29)

#Cybersecurity#JumpServer
Important Notice: JumpServer Vulnerability Advisory and Remediation (JS-2026.7.29)

Important Notice: JumpServer Vulnerability Advisory and Remediation (JS-2026.7.29)

In July 2026, the JumpServer open-source project team received vulnerability reports from security researchers. Upon verification, the following vulnerabilities were identified:

  • JumpServer Chen component Fastjson dependency vulnerability — CVE-2026-16723. Details: fastjson Security Advisory.
  • JumpServer KoKo Web Terminal SFTP path traversal vulnerability — CVE-2026-54336. Details: GHSA-x6rg-36j6-76vr.
  • JumpServer Applet Host deployment Jinja template injection remote command execution vulnerability — CVE-2026-44845. Details: GHSA-22h6-pcgh-9v7q.
  • JumpServer organization invitation logic permission override vulnerability — CVE-2026-44846. Details: GHSA-j836-99w5-523r.

Affected Versions

Version Line Affected Versions Safe Versions
JumpServer V3 < v3.10.22 LTS >= v3.10.22 LTS
JumpServer V4 < v4.10.17 LTS >= v4.10.17 LTS

Exploitation Conditions

1. KoKo Web Terminal SFTP Path Traversal (CVE-2026-54336)

The attacker must possess SFTP access to the target asset. By crafting a special path, the attacker may access files outside the SFTP root directory of the target asset. However, the impact is limited to the scope of currently authorized assets.

2. Applet Host Deployment Jinja Template Injection RCE (CVE-2026-44845)

The attacker must have JumpServer administrator privileges and Applet Host management and deployment permissions. By injecting malicious Jinja template content, the attacker may execute arbitrary commands on the JumpServer control node.

3. Organization Invitation Logic Permission Override (CVE-2026-44846)

The attacker must have organization user invitation permissions. By re-inviting an existing organization member, the attacker may override the target user's current organization role, leading to privilege escalation or privilege reduction.

Remediation

Users are strongly advised to upgrade to the safe versions as soon as possible. In the safe versions, JumpServer has implemented the following fixes:

  • Removed the Fastjson dependency from the Chen component.
  • Fixed the KoKo Web Terminal SFTP path validation logic to prevent path traversal access to files outside restricted directories.
  • Strengthened the Ansible template variable handling mechanism during Applet Host deployment to prevent malicious Jinja template execution on the control node.
  • Fixed the organization invitation logic to prevent incorrect overwriting of user organization roles when re-inviting existing members.

If Immediate Upgrade Is Not Possible

  • Review existing SSH gateway configurations, automation task templates, Applet Host configurations, and organization role change records for anomalous content.
  • Restrict the scope of accounts with user invitation permissions.

Acknowledgments

We would like to thank the following security researchers for submitting vulnerability reports:

  • @g4mm4 for reporting CVE-2026-54336.
  • @PineBlizz for reporting CVE-2026-44845.
  • @skx112 for reporting CVE-2026-44846.

We extend our gratitude to all security researchers for their continued contributions to the security of the JumpServer open-source project.

Recommended Reading

Download Community Free Trial