CVE-2026-53436: Medium severity Jenkins Jenkins vulnerability
Published Jun 10, 2026
·Updated
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains relative path segments (./ or ../), allowing attackers to perform phishing attacks.
Affected Software
4 affected components
Jenkins Jenkins<=2.567
Jenkins Jenkins LTS<=2.555.2
Jenkins Jenkins<2.555.3
Jenkins Jenkins<2.568
Event History
Jun 10, 2026
CVE Published
via MITRE·01:05 PM
Data Sourced
via MITRE·01:05 PM
Description
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-53436?
The severity of CVE-2026-53436 is rated as medium with a CVSS score of 4.3.
2
How do I fix CVE-2026-53436?
To fix CVE-2026-53436, upgrade Jenkins to version 2.568 or later, or LTS 2.555.3 or later.
3
What type of attacks does CVE-2026-53436 enable?
CVE-2026-53436 enables attackers to perform phishing attacks by misdirecting users after login.
4
Which versions of Jenkins are affected by CVE-2026-53436?
Jenkins versions 2.567 and earlier, and LTS 2.555.2 and earlier are affected by CVE-2026-53436.
5
What are the consequences of exploiting CVE-2026-53436?
Exploiting CVE-2026-53436 can lead to unauthorized access and potential phishing of users logged into Jenkins.