CVE-2026-53435: High severity Jenkins Jenkins vulnerability
In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled config.xml submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53435?
The severity of CVE-2026-53435 is high, with a CVSS score of 8.8.
How do I fix CVE-2026-53435?
To fix CVE-2026-53435, upgrade to Jenkins version 2.568 or later.
What types of attacks can CVE-2026-53435 enable?
CVE-2026-53435 can enable attackers to deserialize arbitrary types allowing them to handle HTTP requests.
Which versions of Jenkins are affected by CVE-2026-53435?
Jenkins versions 2.567 and earlier, as well as LTS 2.555.2 and earlier, are affected by CVE-2026-53435.
What components are involved in CVE-2026-53435?
CVE-2026-53435 involves the Jenkins core and its plugins, specifically through modifications in the config.xml file.