CVE-2026-53440: Jenkins
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.
Affected products
- Jenkins Jenkins: before 2.555.3 (fixed in 2.555.3); before 2.568 (fixed in 2.568)
Published 2026-06-10. Last modified 2026-06-17.