← Back to browse · API

CVE-2026-53435

Severity
HIGH
CVSS
8.8
EPSS
0.19035
Risk score
41.86
CISA KEV
No
PoC
Yes
Published
2026-06-10
Modified
2026-07-15
First seen
2026-08-07
Aliases
EUVD-2026-36019, GHSA-G2XQ-2V27-4RH3
Products
Jenkins Project:Jenkins patch: 2.555.3, Jenkins Project:Jenkins patch: 2.568
Sources
euvd EUVD-2026-36019
packetstorm da4665ee27bcfb399a74e0ce|CVE-2026-53435

Description

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.

References