CVE & CISA-KEV Catalog

CVE-2026-31864

MEDIUM
6.8
CVSS v3
NVD

Description

JumpServer is an open source bastion host and an operation and maintenance security audit system. a Server-Side Template Injection (SSTI) vulnerability exists in JumpServer's Applet and VirtualApp upload functionality. This vulnerability can only be exploited by users with administrative privileges (Application Applet Management or Virtual Application Management permissions). Attackers can exploit this vulnerability to execute arbitrary code within the JumpServer Core container. The vulnerability arises from unsafe use of Jinja2 template rendering when processing user-uploaded YAML configuration files. When a user uploads an Applet or VirtualApp ZIP package, the manifest.yml file is rendered through Jinja2 without sandbox restrictions, allowing template injection attacks.

How to fix

Remediation Available
jumpserverNVD
Affected:>= 4.0.0, < 4.10.16Fixed in:4.10.16CVE-2026-31864derived from NVD

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionRequired
ScopeUnchanged

Impact

ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

Exploit Intelligence

0.35%probability of exploitation in 30 days
27thpercentile

Low risk: more likely to be exploited than 27% of all known CVEs.

References

Issue Tracking1
Embed a live status badge for CVE-2026-31864
CVE-2026-31864 severity badge

Markdown

[![CVE-2026-31864](https://tridentstack.com/cve/badge/CVE-2026-31864.svg)](https://tridentstack.com/cve/CVE-2026-31864)

HTML

<a href="https://tridentstack.com/cve/CVE-2026-31864"><img src="https://tridentstack.com/cve/badge/CVE-2026-31864.svg" alt="CVE-2026-31864"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

Start free

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-03-18.