PT-2026-76818 · Unknown · Jumpserver

CVE-2026-54336

·

Published

2026-08-17

·

Updated

2026-08-18

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions JumpServer versions 4.8.0 through 4.10.16
Description An authenticated user with SFTP permission to an authorized asset can submit crafted traversal paths through the KoKo Web Terminal SFTP feature. This causes the AssetDir.GetRealPath() function in pkg/srvconn/sftp asset.go to resolve paths outside the intended SFTP root, allowing read, list, write, rename, or delete operations under the configured backend account on that asset.
Recommendations Update to version 4.10.17.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54336
GHSA-X6RG-36J6-76VR

Affected Products

Jumpserver