FixVibe

high

Jenkins config.xml Deserialization Vulnerability (CVE-2026-53435)

CVE-2026-53435 affects Jenkins core releases through weekly 2.567 and LTS 2.555.2 when attacker-controlled configuration is processed under the required permissions. FixVibe repository scans flag affected Jenkins core versions in Maven or Gradle builds.

CVE-2026-53435GHSA-g2xq-2v27-4rh3CWE-502

Impact

CVE-2026-53435 is a high-severity Jenkins core deserialization vulnerability (CWE-502). In affected Jenkins weekly releases through 2.567 and LTS releases through 2.555.2, an attacker with the required Jenkins permissions may influence configuration processing in a way that can lead to user impersonation, unauthorized controller-file access, or code execution through privileged Jenkins functionality [S1][S2][S3].

The vulnerable behavior depends on the deployed Jenkins controller, its enabled functionality, the permissions held by the account, and how configuration is processed. A repository dependency match does not prove that an affected controller is deployed or reachable.

Root Cause

Jenkins restricts deserialization of Java types, but the affected releases allow an attacker with sufficient access to submit configuration that can cause unexpected types from Jenkins core or plugins to be processed. The Jenkins advisory describes the relevant permission and configuration prerequisites at a high level [S1][S2].

How FixVibe covers it

FixVibe's repository scans flag org.jenkins-ci.main:jenkins-core declarations in Maven or Gradle build files that fall in the affected version ranges, so you can upgrade the controllers built from them.

Remediation

Upgrade Jenkins weekly to 2.568 or later, or Jenkins LTS to 2.555.3 or later, and rebuild or redeploy the controller from the updated dependency. Review who can configure jobs, views, agents, or other Jenkins items, keep controller administration restricted, and verify the running controller version after rollout [S1][S2].