CVE-2026-48920: High severity Jenkins Email Extension Plugin vulnerability
Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as base64 in email content by setting the data-inline attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify file: URLs for images to read arbitrary files from the Jenkins controller filesystem.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48920?
CVE-2026-48920 has a severity rating of 8.8, categorized as high.
How do I fix CVE-2026-48920?
To fix CVE-2026-48920, update the Jenkins Email Extension Plugin to version 1933.v45cec755424 or later.
What are the potential impacts of CVE-2026-48920?
CVE-2026-48920 allows attackers to exploit email content control to specify `file:` URLs, potentially leading to data exposure.
Which software is affected by CVE-2026-48920?
CVE-2026-48920 affects the Jenkins Email Extension Plugin version 1933.v45cec755423f and earlier.
When was CVE-2026-48920 published?
CVE-2026-48920 was published on May 27, 2026.