CVE-2026-48921: High severity Jenkins Pipeline: Groovy Libraries Plugin vulnerability
Jenkins Pipeline: Groovy Libraries Plugin 797.v90eaa9be45a0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48921?
The severity of CVE-2026-48921 is high, rated at 7.5 on the CVSS scale.
How do I fix CVE-2026-48921?
To fix CVE-2026-48921, update to a version of the Jenkins Pipeline: Groovy Libraries Plugin that is later than 797.v90ea_a_9b_e45a_0.
What impact does CVE-2026-48921 have on Jenkins?
CVE-2026-48921 allows attackers to read arbitrary files on the Jenkins controller filesystem due to improper handling of symbolic links.
Who is affected by CVE-2026-48921?
Users of Jenkins Pipeline: Groovy Libraries Plugin version 797.v90ea_a_9b_e45a_0 and earlier are affected by CVE-2026-48921.
What is the nature of the vulnerability described in CVE-2026-48921?
CVE-2026-48921 is a vulnerability that allows unauthorized file access through symbolic links in shared libraries used in Pipeline jobs.