CVE-2026-53436
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Jun 10, 2026
Vendor
unknown
Description
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains relative path segments (`./` or `../`), allowing attackers to perform phishing attacks.