← Back to CVE List
CVE-2026-104126NVD
Vulnerability Summary
An authenticated user with sufficient permissions to create or execute affected Ansible-based automation tasks may invoke unsafe Ansible lookup plugins during JumpServer automation template rendering. By crafting automation content that is rendered by Ansible templates, an attacker may trigger certain lookup plugins such as `pipe`, `env`, `file`, or `password` in the Ansible execution context. This issue requires authenticated access and relevant automation-related permissions. It is not an unauthenticated remote code execution vulnerability.
CVSS v3.1 Base Metrics — Score 6.0
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityLow
AvailabilityLow
Affected & Patched Versions
- JumpServer <=v4.10.16-lts
- JumpServer >=v4.10.17-lts