Known Vulnerabilities for Jenkins by Jenkins Project
Listed below are 10 of the newest known vulnerabilities associated with "Jenkins" by "Jenkins Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-53442 json | Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing t... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-53441 json | Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided ... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-53440 json | Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet cont... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-53439 json | Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission ... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-53438 json | A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permission... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-53437 json | Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately poin... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-53436 json | Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately poin... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-53435 json | In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary typ... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-48927 json | Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-48926 json | Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allowing a... | Not Provided | 2026-05-27 | 2026-05-27 |