PT-2026-48424 · Jenkins+1 · Jenkins+1

CVE-2026-53439

·

Published

2026-06-10

·

Updated

2026-08-12

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins versions prior to 2.567 Jenkins LTS versions prior to 2.555.2
Description Missing permission checks allow attackers with Overall/Read permission to determine the configured timezone of other users and enumerate view names within other users' "My Views".
Recommendations Update to version 2.567 or later. Update to LTS version 2.555.2 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-JENKINS-2026-53439
CVE-2026-53439
GHSA-G28P-6MCC-V4RV

Affected Products

Jenkins
Red Os