What is CVE-2026-54336?
CVE-2026-54336 is a path traversal vulnerability in JumpServer's KoKo Web Terminal SFTP feature. It affects versions 4.8.0 to 4.10.17, allowing an authenticated user with SFTP permission to manipulate file paths and exploit the AssetDir.GetRealPath() function. Users should upgrade to the latest patched version immediately.
Azərbaycanca: CVE-2026-54336 JumpServer-in KoKo Web Terminal SFTP funksiyasında aşkar edilmiş path traversal zəifliyidir. 4.8.0-dan 4.10.17-dək versiyalara təsir edir; autentifikasiyalı istifadəçi AssetDir.GetRealPath() funksiyasını aldadaraq icazəli olduğu asset üzərində fayl yolu manipulyasiyası apara bilər. İstifadəçilər dərhal son versiyaya yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which JumpServer feature does CVE-2026-54336 affect?
This vulnerability affects the KoKo Web Terminal SFTP feature of JumpServer.
What should users do to protect against CVE-2026-54336?
Users should upgrade to the latest patched version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.