Jumpserver
28 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Jumpserver, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
Jumpserver CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 2 |
| 2025-11 | 0 |
| 2025-12 | 1 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 2 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 3 |
| 2026-09 | 0 |
Severity
How the 28 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical7
- High7
- Medium13
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Jumpserver.
- CVE-2026-44846JumpServer: Privilege Overwrite via Organization Invite Logic Flaw6.2
- CVE-2026-44845JumpServer: Remote Command Execution (RCE) via Jinja Template Injection in Applet Host Deployment6.7
- CVE-2026-54336JumpServer: KoKo Web Terminal SFTP Path Traversal on Authorized Asset5.4
- CVE-2026-31864JumpServer has a Server-Side Template Injection Leading to RCE via YAML Rendering6.8
- CVE-2026-31798JumpServer Improper Certificate Validation in Custom SMS API Client5.0
- CVE-2025-58044JumpServer has an Open Redirect Vulnerability6.1
- CVE-2025-62795JumpServer Unauthorized LDAP Configuration Access via WebSocket7.1
- CVE-2025-62712JumpServer Connection Token Leak Vulnerability9.6
- CVE-2025-27095JumpServer has a Kubernetes Token Leak Vulnerability4.3
- CVE-2024-40628Arbitrary File Read in Ansible Playbooks in Jumpserver10.0
- CVE-2024-40629Arbitrary File Write in Ansible Playbooks leads to RCE in Jumpserver10.0
- CVE-2024-29202JumpServer vulnerable to Jinja2 template injection in Ansible leads to RCE in Celery9.9
- CVE-2024-29201JumpServer's insecure Ansible playbook validation leads to RCE in Celery9.9
- CVE-2024-29020JumpServer allows nn authorized attacker to get sensitive information in playbook files when playbook_id is leaked4.6
- CVE-2024-29024JumpServer Direct Object Reference (IDOR) Vulnerability in File Manager Bulk Transfer Functionality4.6
Product grouping is registry-driven, with AI assist and human review. How it works