CVE-2026-54336 is a vulnerability in JumpServer, an open-source bastion host and operation and maintenance security audit system. An authenticated user with SFTP permission can submit crafted traversal paths, allowing read, list, write, rename, or delete operations outside the intended SFTP root. This issue is fixed in version 4.10.17. The vulnerability allows attackers to access unauthorized areas of the [truncated]
CVE-2026-44845 is a vulnerability in JumpServer, an open-source bastion host and operation and maintenance security audit system. An authenticated administrator with Applet Host management and deployment permissions can inject Jinja2 expressions into the IP/Host field or Core Service Address field. This allows Ansible to evaluate ansible_host inventory data or playbook variables during Applet Host deploym [truncated]