CVE-2026-44845: JumpServer: Remote Command Execution (RCE) via Jinja Template Injection in Applet Host Deployment
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an authenticated administrator with Applet Host management and deployment permissions can inject Jinja2 expressions into the IP/Host field or Core Service Address field, causing Ansible to evaluate ansiblehost inventory data or playbook variables during Applet Host deployment and execute arbitrary commands on the JumpServer control node. This issue is fixed in version 4.10.17.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JumpServerto a version that resolves this vulnerability.Fixed in 4.10.17
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44845?
CVE-2026-44845 has a medium severity rating of 6.7.
How do I fix CVE-2026-44845?
To mitigate CVE-2026-44845, update JumpServer to version 4.10.17 or later.
What causes CVE-2026-44845?
CVE-2026-44845 is caused by Jinja2 template injection vulnerabilities in the Applet Host management of JumpServer.
Who is affected by CVE-2026-44845?
Authenticated administrators of JumpServer with Applet Host management and deployment permissions prior to version 4.10.17 are affected by CVE-2026-44845.
What are the potential impacts of CVE-2026-44845?
CVE-2026-44845 allows for remote command execution, which can lead to unauthorized access and control over JumpServer.