Medium severity5.3NVD Advisory· Published Jun 10, 2026· Updated Jun 12, 2026
CVE-2026-53442
CVE-2026-53442
Description
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job configurations unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*+ 2 more
- cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*range: <2.568
- cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*range: <2.555.3
- (no CPE)range: >= 2.555.2, <= 2.567
- osv-coords2 versions
< 2.555.3-r0+ 1 more
- (no CPE)range: < 2.555.3-r0
- (no CPE)range: < 2.555.3
Patches
Vulnerability mechanics
References
1- www.jenkins.io/security/advisory/2026-06-10/nvdVendor Advisory
News mentions
2- Jenkins Core: Eight Vulnerabilities Disclosed Together on June 10, 2026Vypr Intelligence · Jun 10, 2026
- Jenkins Security Advisory 2026-06-10Jenkins Security Advisories · Jun 10, 2026