Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.
References
| Link | Resource |
|---|---|
| https://www.jenkins.io/security/advisory/2026-06-10/#SECURITY-3721 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-06-10 14:16
Updated : 2026-06-17 10:57
NVD link : CVE-2026-53440
Mitre link : CVE-2026-53440
CVE.ORG link : CVE-2026-53440
JSON object : View
Products Affected
jenkins
- jenkins
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
