« Volver al listado

CVE-2026-53435

Estado: ModificadaAlta (8.8)—

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

CVE en Jenkins (servicio remoto) con acceso en red y privilegios requeridos (PR:L). Desserialización arbitraria permite impersonar usuarios, ejecutar código mediante Script Console y leer archivos del controlador.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-53435",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-53435",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-10T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Secondary",
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "jenkinsci-cert@googlegroups.com",
      "affectedData": [
        {
          "vendor": "Jenkins Project",
          "product": "Jenkins",
          "versions": [
            {
              "status": "unaffected",
              "version": "2.568",
              "lessThan": "*",
              "versionType": "maven"
            },
            {
              "status": "unaffected",
              "version": "2.555.3",
              "lessThan": "2.555.*",
              "versionType": "maven"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
      "affectedData": [
        {
          "cpes": [
            "cpe:/a:redhat:ocp_tools:4.12::el8"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Developer Tools and Services 4.12",
          "versions": [
            {
              "status": "unaffected",
              "version": "1786628667",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ocp-tools-4/jenkins-rhel8",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ocp_tools:4.13::el8"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Developer Tools and Services 4.13",
          "versions": [
            {
              "status": "unaffected",
              "version": "1786628681",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ocp-tools-4/jenkins-rhel8",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ocp_tools:4.14::el8"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Developer Tools and Services 4.14",
          "versions": [
            {
              "status": "unaffected",
              "version": "1786533561",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ocp-tools-4/jenkins-rhel8",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ocp_tools:4.15::el8"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Developer Tools and Services 4.15",
          "versions": [
            {
              "status": "unaffected",
              "version": "1786533565",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ocp-tools-4/jenkins-rhel8",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ocp_tools:4.16::el9"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Developer Tools and Services 4.16",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787125166",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ocp-tools-4/jenkins-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ocp_tools:4.17::el9"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Developer Tools and Services 4.17",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787124635",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ocp-tools-4/jenkins-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ocp_tools:4.18::el9"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Developer Tools and Services 4.18",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787125069",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ocp-tools-4/jenkins-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ocp_tools:4.19::el9"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Developer Tools and Services 4.19",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787124632",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ocp-tools-4/jenkins-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ocp_tools:4.20::el9"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Developer Tools and Services 4.20",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787124925",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ocp-tools-4/jenkins-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ocp_tools:4.21::el9"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Developer Tools and Services 4.21",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787125311",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ocp-tools-4/jenkins-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ocp_tools:4.22::el9"
          ],
          "vendor": "Red Hat",
          "product": "OpenShift Developer Tools and Services 4.22",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787124779",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "ocp-tools-4/jenkins-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-06-10T14:16:36.440",
  "references": [
    {
      "url": "https://www.jenkins.io/security/advisory/2026-06-10/#SECURITY-3707",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "jenkinsci-cert@googlegroups.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:60239",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:60246",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:60247",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:60248",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:60249",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:60250",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:60251",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:60252",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:60254",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:60256",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:60259",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2026-53435",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487539",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53435.json",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-502"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
      "description": [
        {
          "lang": "en",
          "value": "CWE-502"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards.\nThis can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller."
    }
  ],
  "lastModified": "2026-08-27T13:18:23.727",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "648B5148-FE3B-464A-8963-DCF7ACEF84E5",
              "versionEndExcluding": "2.555.3"
            },
            {
              "criteria": "cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "356A970F-6576-49B6-8EBA-E9770ED190A7",
              "versionEndExcluding": "2.568"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "jenkinsci-cert@googlegroups.com"
}