PT-2026-76813 · Unknown · Jumpserver

CVE-2026-44846

·

Published

2026-08-17

·

Updated

2026-08-18

CVSS v3.1

6.2

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions JumpServer versions prior to 4.10.17
Description A user possessing the users.invite user permission can submit an existing member via the 'POST /api/v1/users/users/invite/' endpoint. This triggers the organization invitation logic within apps/users/api/user.py to execute the user.org roles.set(org roles) function, which replaces the member's current organization roles. This flaw allows for privilege escalation or the downgrading of administrators.
Recommendations Update to version 4.10.17.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44846
GHSA-J836-99W5-523R

Affected Products

Jumpserver