CVE-2026-53439: Medium severity Jenkins Jenkins vulnerability
Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other users' configured timezone and to enumerate view names of other users' "My Views".
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Review Jenkins global security/authorization settings and ensure the Overall/Read permission is granted only to trusted accounts; remove this permission from anonymous, unauthenticated, or otherwise untrusted users/groups.
Jenkins Overall/Read permission = revoke from untrusted users - Compensating control
Restrict access to the Jenkins web UI and management endpoints to trusted IP ranges via network controls (firewall, reverse proxy, or VPN) to limit who can exercise Overall/Read and reduce exposure.
- Operational
Audit all accounts and groups that currently have Overall/Read permission, remove unnecessary assignments, and record justification for any retained access.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53439?
The severity of CVE-2026-53439 is classified as medium with a CVSS score of 4.3.
How do I fix CVE-2026-53439?
To fix CVE-2026-53439, upgrade Jenkins to version 2.568 or later, or LTS 2.556 or later.
What type of vulnerability is CVE-2026-53439?
CVE-2026-53439 is a missing permission check vulnerability affecting Jenkins.
What can attackers do with CVE-2026-53439?
Attackers with Overall/Read permission can determine other users' configured timezone and enumerate other users' view names.
Which versions of Jenkins are affected by CVE-2026-53439?
Jenkins versions 2.567 and earlier, and LTS 2.555.2 and earlier are affected by CVE-2026-53439.