CVE-2026-53438: Jenkins
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permission, but lacking Item/Read permission, to cancel queue items they do not have permission to view.
Affected products
- Jenkins Jenkins: before 2.555.3 (fixed in 2.555.3); before 2.568 (fixed in 2.568)
Published 2026-06-10. Last modified 2026-06-17.