Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-53435 Details

Description

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-502Deserialization of Untrusted Dataredhat-SADP
CWE-502Deserialization of Untrusted DataCISA-ADP

Affected Products

ProductVersions
jenkins jenkins
< 2.555.3
< 2.568

CPE

  • cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
  • cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*

Remediation

  • No remediation found in references.

Change History

11 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-53435
NVD Published Date:
Jun 10, 2026
NVD Last Modified:
Aug 27, 2026
Source:
[email protected]
CVE-2026-53435 Details - Not Deferred