MEDIUMCVSS 4.3EPSS 0.2%
CVE-2026-53440
Jenkins: Open Redirect phishing attacks possible via "from" parameter in "Delegate to servlet container"
Summary
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.
Affected packages
| Ecosystem | Package | Affected versions | Fixed versions |
|---|---|---|---|
| Maven | org.jenkins-ci.main:jenkins-core | — | 2.555.3, 2.568 |
Remediation: Upgrade to 2.555.3 or later.
References
Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.
EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.