CVE-2026-53439: Jenkins

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other users' configured timezone and to enumerate view names of other users' "My Views".

Affected products

  • Jenkins Jenkins: before 2.555.3 (fixed in 2.555.3); before 2.568 (fixed in 2.568)

Published 2026-06-10. Last modified 2026-06-17.