No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 10 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Open Redirect Allows Phishing via Jenkins Login Redirect |
Wed, 10 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 10 Jun 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins Project
Jenkins Project jenkins |
|
| Vendors & Products |
Jenkins Project
Jenkins Project jenkins |
Wed, 10 Jun 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Open Redirect Allows Phishing via Jenkins Login Redirect | |
| Weaknesses | CWE-601 |
Wed, 10 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-06-10T14:39:11.982Z
Reserved: 2026-06-09T14:26:44.789Z
Link: CVE-2026-53440
No data.
Status : Undergoing Analysis
Published: 2026-06-10T14:16:36.990
Modified: 2026-06-10T19:43:28.857
Link: CVE-2026-53440
No data.
OpenCVE Enrichment
Updated: 2026-06-10T18:15:17Z