PT-2026-48427 · Jenkins+1 · Jenkins+1

CVE-2026-53442

·

Published

2026-06-10

·

Updated

2026-08-12

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins versions prior to 2.568 Jenkins LTS versions prior to 2.555.3
Description Secrets provided via POST config.xml submissions are stored unencrypted in job configuration files on the Jenkins controller. This allows users with Item/Extended Read permissions or direct access to the controller file system to view these secrets.
Recommendations Update to version 2.568 or later. Update to LTS version 2.555.3 or later.

Fix

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-JENKINS-2026-53442
CVE-2026-53442
GHSA-M6WV-WH8G-64XC

Affected Products

Jenkins
Red Os