Impact
CVE-2026-53435 is a high-severity Jenkins core deserialization vulnerability (CWE-502). In affected Jenkins weekly releases through 2.567 and LTS releases through 2.555.2, an attacker with the required Jenkins permissions may influence configuration processing in a way that can lead to user impersonation, unauthorized controller-file access, or code execution through privileged Jenkins functionality [S1][S2][S3].
The vulnerable behavior depends on the deployed Jenkins controller, its enabled functionality, the permissions held by the account, and how configuration is processed. A repository dependency match does not prove that an affected controller is deployed or reachable.
Root Cause
Jenkins restricts deserialization of Java types, but the affected releases allow an attacker with sufficient access to submit configuration that can cause unexpected types from Jenkins core or plugins to be processed. The Jenkins advisory describes the relevant permission and configuration prerequisites at a high level [S1][S2].
How FixVibe covers it
FixVibe's repository scans flag org.jenkins-ci.main:jenkins-core declarations in Maven or Gradle build files that fall in the affected version ranges, so you can upgrade the controllers built from them.
Remediation
Upgrade Jenkins weekly to 2.568 or later, or Jenkins LTS to 2.555.3 or later, and rebuild or redeploy the controller from the updated dependency. Review who can configure jobs, views, agents, or other Jenkins items, keep controller administration restricted, and verify the running controller version after rollout [S1][S2].
