CVE-2026-53435: Vulnerability in Jenkins Project Jenkins
In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.
AI Analysis
Technical Summary
This vulnerability involves Jenkins deserializing arbitrary types defined in Jenkins core or plugins from attacker-controlled config.xml submissions. Exploitation allows attackers to handle HTTP requests as any user, potentially leveraging the Script Console to execute arbitrary code or read sensitive files on the Jenkins controller. The affected versions are Jenkins 2.567 and earlier, including LTS 2.555.2 and earlier. The CVSS v3.1 base score is 8.8, indicating high severity with network attack vector, low attack complexity, requiring low privileges but no user interaction, and resulting in high confidentiality, integrity, and availability impacts. No official remediation level or patch information is provided in the input data. The Red Hat advisory URL is given but does not specify patch status in the provided content.
Potential Impact
Successful exploitation can lead to full compromise of the Jenkins controller, including arbitrary code execution via the Script Console, impersonation of any user, unauthorized HTTP requests on behalf of users, and reading arbitrary files. This poses a critical risk to the confidentiality, integrity, and availability of the Jenkins environment and potentially connected systems.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The provided Red Hat advisory link should be monitored for updates. Until an official fix is available, restrict access to Jenkins config.xml submissions to trusted users only and consider isolating Jenkins controllers to limit exposure.
CVE-2026-53435: Vulnerability in Jenkins Project Jenkins
Description
In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.
CVSS v3.1
Score 8.8high
Affected software
pkg:github/jenkinsci/jenkinsRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves Jenkins deserializing arbitrary types defined in Jenkins core or plugins from attacker-controlled config.xml submissions. Exploitation allows attackers to handle HTTP requests as any user, potentially leveraging the Script Console to execute arbitrary code or read sensitive files on the Jenkins controller. The affected versions are Jenkins 2.567 and earlier, including LTS 2.555.2 and earlier. The CVSS v3.1 base score is 8.8, indicating high severity with network attack vector, low attack complexity, requiring low privileges but no user interaction, and resulting in high confidentiality, integrity, and availability impacts. No official remediation level or patch information is provided in the input data. The Red Hat advisory URL is given but does not specify patch status in the provided content.
Potential Impact
Successful exploitation can lead to full compromise of the Jenkins controller, including arbitrary code execution via the Script Console, impersonation of any user, unauthorized HTTP requests on behalf of users, and reading arbitrary files. This poses a critical risk to the confidentiality, integrity, and availability of the Jenkins environment and potentially connected systems.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The provided Red Hat advisory link should be monitored for updates. Until an official fix is available, restrict access to Jenkins config.xml submissions to trusted users only and consider isolating Jenkins controllers to limit exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- jenkins
- Date Reserved
- 2026-06-09T14:26:44.788Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-53435","vendor":"Red Hat"}]
Threat ID: 6a2967b2c9170919df1fd8fd
Added to database: 06/10/2026, 13:33:38 UTC
Last enriched: 07/18/2026, 14:50:47 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 691
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.