CVE-2026-44845
Last modified
CVE-2026-44845 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an authenticated administrator with Applet Host management and deployment permissions can inject Jinja2 expressions into the IP/Host field or Core Service Address field, causing Ansible to evaluate ansible_host inventory data or playbook variables during Applet Host deployment and execute arbitrary commands on the JumpServer control node. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an authenticated administrator with Applet Host management and deployment permissions can inject Jinja2 expressions into the IP/Host field or Core Service Address field, causing Ansible to evaluate ansible_host inventory data or playbook variables during Applet Host deployment and execute arbitrary commands on the JumpServer control node. This issue is fixed in version 4.10.17.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| jumpserver | jumpserver | < 4.10.17 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-44845?
How severe is CVE-2026-44845?
How do I fix CVE-2026-44845?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-44838RabbitMQ is a messaging and streaming broker. From 4.2.0 to …8.1
- CVE-2026-44839RabbitMQ is a messaging and streaming broker. From 3.7.0 to …4.8
- CVE-2026-4484The Masteriyo LMS plugin for WordPress is vulnerable to Priv…8.8
- CVE-2026-44840Dgraph is an open source distributed GraphQL database. Prior…7.5
- CVE-2026-44843LangChain is a framework for building agents and LLM-powered…8.2
- CVE-2026-44844eml_parser serves as a python module for parsing eml files a…6.3
- CVE-2026-44846JumpServer is an open source bastion host and an operation a…6.2
- CVE-2026-44847MaxKB is an open-source AI assistant for enterprise. Prior t…7.5
- CVE-2026-44848Portainer Community Edition is a lightweight service deliver…8.8
- CVE-2026-44849Portainer Community Edition is a lightweight service deliver…8.8
- CVE-2026-4485A vulnerability has been found in itsourcecode College Manag…6.3
- CVE-2026-44850Portainer Community Edition is a lightweight service deliver…8.5
Are you affected by CVE-2026-44845?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
