tag
Jenkins
CVE-2026-53435
web
HIGH 9.1
EPSS 19%
Jenkins ClassFilter Deserialization Bypass → Arbitrary File Read — CVE-2026-53435
Jenkins restricts deserialization via a custom ClassFilter that only allows types defined in Jenkins core or installed plugins. CVE-2026-53435 shows this whitelist is insufficient: an attacker who can POST a view's config.xml can get Jenkins to deserialize a…
Patched
2026-07-05
CVE-2024-23897
web
CRITICAL 9.8
KEV
Ransomware
EPSS 100%
Jenkins CLI Arbitrary File Read to RCE (CVE-2024-23897)
CVE-2024-23897 is an arbitrary file read vulnerability in the Jenkins CLI command parser. The parser expands arguments that start with @ and can disclose controller-local files to unauthenticated attackers in common deployments. This disclosure can expose…
Patched
2026-05-17