What is CVE-2026-44846?
CVE-2026-44846 is a vulnerability in JumpServer versions prior to 4.10.17 where a user with the "users.invite_user" permission can submit an existing member to the "POST /api/v1/users/users/invite/" endpoint, causing an issue in the organization invitation logic. Users are advised to upgrade to version 4.10.17 or later.
Azərbaycanca: CVE-2026-44846 JumpServer-in köhnə versiyalarında (4.10.17-dən əvvəl) aşkarlanmış zəiflikdir. Bu zəiflik "users.invite_user" icazəsinə malik istifadəçiyə artıq mövcud olan üzvü "POST /api/v1/users/users/invite/" sorğusu ilə yenidən dəvət etməyə imkan verir ki, bu da təşkilat dəvət məntiqində problemə səbəb olur. İstifadəçilərə JumpServer-i 4.10.17 və ya daha yeni versiyaya yeniləmələri tövsiyə olunur.
FAQ2
Which versions of JumpServer are affected by CVE-2026-44846?
This vulnerability affects JumpServer versions prior to 4.10.17.
What is recommended to users to fix the CVE-2026-44846 vulnerability?
Users are advised to upgrade JumpServer to version 4.10.17 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.