Jenkins
Jenkins Security Advisory 2026-06-10
2026-06-10 Jun 10, 2026 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2026-06-10/. 6 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2026-06-10/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
8 lines
Showing 1–8 of 8
Acknowledgement
BR2026-0000-007314
SECURITY-3711
unclaimed
SECURITY-3711
Credited as Takumi Katanoda (SECURITY-3711); Fushuling@secsys from Fudan University and RacerZ@secsys from Fudan University; and, independently, Michael Blunt (SECURITY-3755)
CVE-2026-53440
BR2026-0000-007315
SECURITY-3721
unclaimed
Open redirect vulnerability in "Delegate to servlet container" security realm
Credited as Takumi Katanoda, and, independently, Kartik T Nair (@k0w4lzk1) from Team bi0s
CVE-2026-53435
BR2026-0000-007316
SECURITY-3707
unclaimed
Deserialization vulnerability
Credited as dqh1
CVE-2026-53442
BR2026-0000-007317
SECURITY-3744
unclaimed
Plaintext secrets persisted and served by config.xml endpoints
Credited as quannn
CVE-2026-53442
BR2026-0000-007318
SECURITY-3744
unclaimed
Plaintext secrets persisted and served by config.xml endpoints
Credited as vstxckr
CVE-2026-53439
BR2026-0000-007319
SECURITY-3713
unclaimed
Missing permission checks allow obtaining limited user profile information
Credited as sam91281
CVE-2026-53438
BR2026-0000-007320
SECURITY-3712
unclaimed
Missing permission check allows canceling queue items
Credited as sam91281; and, independently, Aries441
CVE-2026-53441
BR2026-0000-007321
SECURITY-3731
unclaimed
Stored XSS vulnerability in node offline cause description
Credited as wooseokdotkim