Improper Certificate Validation in JumpServer - CVE-2026-31798
Published: April 27, 2026
JumpServer
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass multi-factor authentication and gain unauthorized access to accounts.
The vulnerability exists due to improper certificate validation in the custom SMS API client when sending OTP codes to a custom SMS API over HTTPS. A remote attacker can perform a man-in-the-middle interception with a bogus certificate to capture the verification code and bypass multi-factor authentication and gain unauthorized access to accounts.
User interaction is required because a victim must initiate a login flow that triggers delivery of an OTP code.