CVE-2026-44846: JumpServer: Privilege Overwrite via Organization Invite Logic Flaw
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, a user with the users.inviteuser permission can submit an existing member to POST /api/v1/users/users/invite/, causing the organization invitation logic in apps/users/api/user.py to execute user.orgroles.set(orgroles) and replace the member's existing organization roles, which can escalate privileges or downgrade administrators. This issue is fixed in version 4.10.17.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JumpServerto a version that resolves this vulnerability.Fixed in 4.10.17
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44846?
The severity of CVE-2026-44846 is medium, with a score of 6.2.
How do I fix CVE-2026-44846?
To fix CVE-2026-44846, upgrade JumpServer to version 4.10.17 or later.
What impact does CVE-2026-44846 have on JumpServer?
CVE-2026-44846 allows a user with invitation permissions to potentially overwrite privileges of existing members.
Is CVE-2026-44846 exploitable remotely?
Yes, CVE-2026-44846 is exploitable remotely due to lack of proper permissions validation during the invitation process.
What software is affected by CVE-2026-44846?
CVE-2026-44846 affects JumpServer versions prior to 4.10.17.