Description
In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
- Что ж ты, Жека? Разбираем критическую уязвимость в Jenkinsru-ru·Хакер (xakep.ru)· PoC Jenkins rce
- 2,060 New CVEs and 4 Actively Exploited Flaws (June 15-21, 2026)en-us·Daily CyberSecurity (securityonline.info)· Exploited Splunk Enterprise zero-day
- Jenkins RCE Vulnerability CVE-2026-53435 Now Under Active Exploitationen-us·Daily CyberSecurity (securityonline.info)· Exploited Jenkins (controllers) rce
- Critical Jenkins Security Advisory 2026: Patch Multiple Flawsen-us·Daily CyberSecurity (securityonline.info)· Patch Jenkins rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-53435 and every CVE in our database. Create a free account — no credit card required.
Create Free Account