Important Notice: JumpServer Vulnerability Advisory and Remediation (JS-2026.09.09)
JumpServer security advisory JS-2026.09.09: an improper API filtering vulnerability (GHSA-6rp5-ff2m-qfrm, High, CVSS 8.8) lets any authenticated user retrieve administrator Access Keys by appending a query parameter. Affects V3 >= v3.7.0 and < v3.10.23 LTS, and V4 >= v4.0.0 and < v4.10.19 LTS. Upgrade or apply the Nginx workaround immediately.