A AegiFlow
MEDIUMCVSS 4.3EPSS 0.2%

CVE-2026-53440

Jenkins: Open Redirect phishing attacks possible via "from" parameter in "Delegate to servlet container"

Published
2026-06-10
Modified
2026-08-13
EPSS percentile
15%
Aliases
GHSA-92m7-4fpw-2wxm
Sources
github-advisory

Summary

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenorg.jenkins-ci.main:jenkins-core2.555.3, 2.568

Remediation: Upgrade to 2.555.3 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.