CVE-2026-53441

June 10, 2026, 2:16 p.m.

None
No Score

Description

Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the `POST config.xml` API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.

Product(s) Impacted

Vendor Product Versions
Jenkins
  • Jenkins
  • Jenkins Lts
  • 2.483-2.567
  • 2.492.1-2.555.2

Weaknesses

Common security weaknesses mapped to this vulnerability.

*CPE(s)

Affected systems and software identified for this CVE.

Type Vendor Product Version Update Edition Language Software Edition Target Software Target Hardware Other Information
a jenkins jenkins 2.483-2.567 / / / / / / /
a jenkins jenkins_lts 2.492.1-2.555.2 / / / / / / /

Timeline

Published: June 10, 2026, 2:16 p.m.
Last Modified: June 10, 2026, 2:16 p.m.

Status : Received

CVE has been recently published to the CVE List and has been received by the NVD.

More info

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.