JumpServer patches QVD-2026-65008 AccessKey disclosure flaw
In September 2026, open-source bastion host JumpServer fixed vulnerability QVD-2026-65008 (CVSS 8.8), which let an unauthenticated attacker retrieve all users' AccessKeys and temporary tokens. Chinese vendor Qianxin counted roughly 19,000 at-risk assets in China; fixes shipped in LTS builds v3.10.23 and v4.10.19.
- QVD-2026-65008 carries a CVSS 3.1 score of 8.8
- The flaw returned all users' AccessKeys and tokens without authentication
- About 19,000 at-risk JumpServer assets counted in China
- Fixes released in LTS versions v3.10.23 and v4.10.19
Read next
Security