CVE-2026-53441: XSS
Published Jun 10, 2026
·Updated
Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the POST config.xml API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
Affected Software
4 affected components
Jenkins Jenkins>=2.483<=2.567
Jenkins Jenkins LTS>=2.492.1<=2.555.2
Jenkins Jenkins>=2.483<2.568
Jenkins Jenkins>=2.492.1<2.555.3
Event History
Jun 10, 2026
CVE Published
via MITRE·01:06 PM
Data Sourced
via MITRE·01:06 PM
Description
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-53441?
CVE-2026-53441 has a risk rating of 28, indicating a medium to high severity level.
2
How do I fix CVE-2026-53441?
To fix CVE-2026-53441, upgrade Jenkins to version 2.568 or later.
3
What types of systems are affected by CVE-2026-53441?
CVE-2026-53441 affects Jenkins versions 2.483 through 2.567 and LTS versions 2.492.1 through 2.555.2.
4
What kind of vulnerability is CVE-2026-53441?
CVE-2026-53441 is identified as a stored cross-site scripting (XSS) vulnerability.
5
Can CVE-2026-53441 be exploited remotely?
Yes, CVE-2026-53441 can be exploited remotely through the `POST config.xml` API.