CVE-2026-53440
Last modified
CVE-2026-53440 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Jenkins | < 2.555.3 |
| Jenkins | Jenkins | < 2.568 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-53440?
How severe is CVE-2026-53440?
How do I fix CVE-2026-53440?
Are you affected by CVE-2026-53440?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
