PT-2026-48423 · Jenkins+1 · Jenkins+1

CVE-2026-53438

·

Published

2026-06-10

·

Updated

2026-08-12

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins versions prior to 2.568 Jenkins LTS versions prior to 2.555.3
Description A missing permission check allows attackers who possess the Item/Cancel permission, but lack the Item/Read permission, to cancel queue items that they are not authorized to view.
Recommendations Update to version 2.568 or later. Update to LTS version 2.555.3 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-JENKINS-2026-53438
CVE-2026-53438
GHSA-MW82-XCG6-GX79

Affected Products

Jenkins
Red Os