Skip to content

Product Introduction⚓︎

[Important Notice | JumpServer Vulnerability Notification and Remediation (JS-2026.7.29)]

In July 2026, the JumpServer open source project team received vulnerability reports from security researchers. After verification, the following vulnerabilities were confirmed:

Vulnerability in the fastjson dependency of the JumpServer Chen component (CVE-2026-16723). Details: Security Advisory: Remote Code Execution in fastjson 1.2.68-1.2.83

SFTP path traversal in JumpServer KoKo Web Terminal (CVE-2026-54336). Details: GHSA-x6rg-36j6-76vr

Remote command execution through Jinja template injection during JumpServer Applet Host deployment (CVE-2026-44845). Details: GHSA-22h6-pcgh-9v7q

Privilege overwrite in JumpServer organization invitation logic (CVE-2026-44846). Details: GHSA-j836-99w5-523r

Affected versions:


JumpServer V3: earlier than v3.10.22 LTS
JumpServer V4: earlier than v4.10.17 LTS

Secure versions:


JumpServer V3: v3.10.22 LTS or later
JumpServer V4: v4.10.17 LTS or later

If an immediate upgrade is not possible:

Restrict administrative access to high-risk functionality such as Ansible automation, SSH gateways, and Applet Hosts, granting the relevant permissions only to trusted administrators;

Review existing SSH gateway configurations, automation task templates, Applet Host configurations, and organization role change records for suspicious content;

Limit the use of accounts that have user invitation permissions.

1 What is JumpServer?⚓︎

JumpServer is a popular open source bastion machine that is a professional operation and maintenance security audit system conforming to the 4A specification. JumpServer helps enterprises manage and log in to all types of assets in a more secure way, implementing pre-authorization, in-process monitoring, and post-audit to meet compliance requirements.

index_02

JumpServer bastion machine supports the following asset types:

  • SSH (Linux / Unix / Network devices, etc.)
  • Windows (Web access / native RDP access)
  • Database (MySQL / MariaDB / Oracle / SQL Server / PostgreSQL / ClickHouse, etc.)
  • NoSQL (Redis / MongoDB, etc.)
  • GPT (ChatGPT, etc.)
  • Cloud services (Kubernetes / VMware vSphere, etc.)
  • Web sites (Web management backends of various systems)
  • Applications (various applications accessed through Remote App)

Documentation Guide

Official Website       Installation and Deployment       Online Demo       Enterprise Edition Trial       Community Forum       Video Teaching       Technical Whitepaper

2 Product Features⚓︎

JumpServer product features include:

  • Open source: Zero threshold, quickly obtain and install online
  • Distributed: Easily support large-scale concurrent access
  • Plugin-free: Browser only, ultimate Web Terminal experience
  • Multi-cloud support: One system managing assets across different clouds
  • Cloud storage: Audit recordings stored in cloud, never lost
  • Multi-tenant: One system for multiple subsidiaries and departments
  • Multi-application support: Database, Windows remote applications, Kubernetes

3 Page Display⚓︎

!Interface Display

4 Application Store⚓︎

JumpServer's remote application feature supports Chrome and DBeaver applications by default in community edition, and supports richer remote applications in enterprise edition. Click Application Store to get more remote applications.

5 Security Statement⚓︎

6 Commercial Products⚓︎

7 Learn More⚓︎