---
id: CVE-2026-54336
title: >-
  JumpServer is an open source bastion host and an operation and maintenance
  security audit system
summary: >-
  JumpServer is an open source bastion host and an operation and maintenance
  security audit system. From 4.8.0 until 4.10.17, an authenticated user with
  SFTP permission to an authorized asset can submit crafted traversal paths
  through the …
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-22
published: '2026-08-17'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:11:46.833'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-54336'
references:
  - url: >-
      https://github.com/jumpserver/jumpserver/security/advisories/GHSA-x6rg-36j6-76vr
    label: security-advisories@github.com
  - url: >-
      https://github.com/jumpserver/koko/commit/02fabebe27dacce89114fba122c667a946fd12ea
    label: security-advisories@github.com
  - url: 'https://github.com/jumpserver/koko/releases/tag/v4.10.17'
    label: security-advisories@github.com
  - url: >-
      https://github.com/jumpserver/jumpserver/security/advisories/GHSA-x6rg-36j6-76vr
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00341
epssPercentile: 0.24863
ingestedAt: '2026-09-09T21:22:45.536Z'
---

## Overview

JumpServer is an open source bastion host and an operation and maintenance security audit system. From 4.8.0 until 4.10.17, an authenticated user with SFTP permission to an authorized asset can submit crafted traversal paths through the KoKo Web Terminal SFTP feature, causing AssetDir.GetRealPath() in pkg/srvconn/sftp_asset.go to resolve paths outside the intended SFTP root and permit read, list, write, rename, or delete operations under the configured backend account on that asset. This issue is fixed in version 4.10.17.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
