Medium severity5.3NVD Advisory· Published Jun 10, 2026· Updated Jun 12, 2026
CVE-2026-53442
CVE-2026-53442
Description
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job configurations unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.main:jenkins-coreMaven | < 2.555.3 | 2.555.3 |
org.jenkins-ci.main:jenkins-coreMaven | >= 2.556, < 2.568 | 2.568 |
Affected products
5- osv-coords2 versions
< 2.555.3-r0+ 1 more
- (no CPE)range: < 2.555.3-r0
- (no CPE)range: < 2.555.3
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*range: <2.555.3
- cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*range: <2.568
- (no CPE)range: >= 2.555.2, <= 2.567
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-m6wv-wh8g-64xcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-53442ghsaADVISORY
- www.jenkins.io/security/advisory/2026-06-10/nvdVendor AdvisoryWEB
- github.com/jenkinsci/jenkins/commit/037c2c30cd26b926ec9df3d1b60e16b80608edb4ghsaWEB
- github.com/jenkinsci/jenkins/commit/206f0b565f0ce16b5162160ffb96f5dd59002ff7ghsaWEB
News mentions
2- Jenkins Core: Eight Vulnerabilities Disclosed Together on June 10, 2026Vypr Intelligence · Jun 10, 2026
- Jenkins Security Advisory 2026-06-10Jenkins Security Advisories · Jun 10, 2026