Medium severity4.3NVD Advisory· Published Jun 10, 2026· Updated Jun 12, 2026
CVE-2026-53440
CVE-2026-53440
Description
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.main:jenkins-coreMaven | < 2.555.3 | 2.555.3 |
org.jenkins-ci.main:jenkins-coreMaven | >= 2.556, < 2.568 | 2.568 |
Affected products
5- osv-coords2 versions
< 2.555.3-r0+ 1 more
- (no CPE)range: < 2.555.3-r0
- (no CPE)range: < 2.555.3
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*range: <2.555.3
- cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*range: <2.568
- (no CPE)range: <=2.567, <=2.555.2 (LTS)
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-92m7-4fpw-2wxmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-53440ghsaADVISORY
- www.jenkins.io/security/advisory/2026-06-10/nvdVendor AdvisoryWEB
- github.com/jenkinsci/jenkins/commit/38071826c9a2113e1104714595262827a87b392fghsaWEB
- github.com/jenkinsci/jenkins/commit/c45e93f2d77d94ea3b0545eb5aca32b808a27586ghsaWEB
News mentions
2- Jenkins Core: Eight Vulnerabilities Disclosed Together on June 10, 2026Vypr Intelligence · Jun 10, 2026
- Jenkins Security Advisory 2026-06-10Jenkins Security Advisories · Jun 10, 2026