What is CVE-2026-44845?
CVE-2026-44845 is a Jinja2 template injection vulnerability in JumpServer, an open source bastion host system. An authenticated administrator with Applet Host management permissions can inject malicious code into the IP/Host or Core Service Address fields, potentially leading to command execution via Ansible. Users should update to version 4.10.17.
Azərbaycanca: CVE-2026-44845 JumpServer açıq mənbəli bastion host sistemində autentifikasiya olunmuş administrator tərəfindən Jinja2 şablon inyeksiyası zəifliyidir. Bu, Applet Host idarəetmə icazələri olan şəxsə IP/Host və ya Core Service Address sahələrinə zərərli kod daxil etməyə imkan verir və Ansible vasitəsilə əmrlərin icrasına səbəb ola bilər. İstifadəçilərə 4.10.17 versiyasına yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which version of JumpServer fixes the CVE-2026-44845 vulnerability?
Users should update to version 4.10.17.
What permissions must an attacker have to exploit the CVE-2026-44845 vulnerability?
The attacker must be an authenticated administrator with Applet Host management permissions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.