No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 18 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jumpserver
Jumpserver jumpserver |
|
| Vendors & Products |
Jumpserver
Jumpserver jumpserver |
Mon, 17 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, a user with the users.invite_user permission can submit an existing member to POST /api/v1/users/users/invite/, causing the organization invitation logic in apps/users/api/user.py to execute user.org_roles.set(org_roles) and replace the member's existing organization roles, which can escalate privileges or downgrade administrators. This issue is fixed in version 4.10.17. | |
| Title | JumpServer: Privilege Overwrite via Organization Invite Logic Flaw | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-18T13:13:42.335Z
Reserved: 2026-05-07T21:21:48.353Z
Link: CVE-2026-44846
Updated: 2026-08-18T13:13:29.931Z
Status : Received
Published: 2026-08-17T21:16:45.227
Modified: 2026-08-18T14:17:07.820
Link: CVE-2026-44846
No data.
OpenCVE Enrichment
Updated: 2026-08-18T00:15:03Z