A vulnerability classified as very critical was found in JumpServer up to 4.10.16. This affects an unknown function of the file apps/users/api/user.py of the component Organization Invitation Logic. Such manipulation leads to improper privilege management.

This vulnerability is traded as CVE-2026-44846. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is advised.