216.73.217.22

CVE-2026-53435

· Published 10/06/2026 14:16 · Modified 11/06/2026 13:26

Labels: CVE-2026-53435 2026-06-10CVE-2026-53435CWE-502[email protected]

Essential information

Published
10/06/2026 14:16
Modified
11/06/2026 13:26
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
jenkins / jenkins cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
jenkins / jenkins cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*

References