SCA: security update for org.jenkins-ci.main:jenkins-core (GHSA-g2xq-2v27-4rh3)

high Tenable Cloud Security Plugin ID 445955

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins
deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml`
submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate
any user and send HTTP requests on their behalf, up to and including use of the Script Console to run
arbitrary code, or to read arbitrary files from the Jenkins controller. (CVE-2026-53435)

Solution

Update the org.jenkins-ci.main:jenkins-core library and its related packages to version 2.555.3 or later.

See Also

https://github.com/advisories/GHSA-g2xq-2v27-4rh3

Plugin Details

Severity: High

ID: 445955

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/13/2026

Updated: 8/13/2026

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.44

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-53435

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/10/2026

Vulnerability Publication Date: 6/10/2026

Reference Information

CVE: CVE-2026-53435

cwe: CWE-502