PT-2026-48425 · Jenkins+1 · Jenkins+1

CVE-2026-53440

·

Published

2026-06-10

·

Updated

2026-08-12

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins versions prior to 2.568 Jenkins LTS versions prior to 2.555.3
Description The "Delegate to servlet container" security realm fails to validate that the from parameter is a safe destination for redirection after login. This allows attackers to redirect users to an external domain under their control, facilitating phishing attacks.
Recommendations Update to version 2.568 or later. Update to LTS version 2.555.3 or later.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-JENKINS-2026-53440
CVE-2026-53440
GHSA-92M7-4FPW-2WXM

Affected Products

Jenkins
Red Os