PT-2026-76812 · Unknown · Jumpserver

CVE-2026-44845

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v3.1

6.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:H
Name of the Vulnerable Software and Affected Versions JumpServer versions prior to 4.10.17
Description An authenticated administrator with Applet Host management and deployment permissions can inject Jinja2 expressions into the IP/Host field or the Core Service Address field. This allows Ansible to evaluate ansible host inventory data or playbook variables during Applet Host deployment, leading to arbitrary command execution on the JumpServer control node. Jinja2 is a templating engine for Python used to generate dynamic content.
Recommendations Update to version 4.10.17.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44845
GHSA-22H6-PCGH-9V7Q

Affected Products

Jumpserver