๐Ÿ” CVE Alert

CVE-2026-48921

HIGH 7.5
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.

Vendor jenkins project
Product jenkins pipeline: groovy libraries plugin
Published May 27, 2026
Last Updated May 27, 2026
Stay Ahead of the Next One

Get instant alerts for jenkins project jenkins pipeline: groovy libraries plugin

Be the first to know when new high vulnerabilities affecting jenkins project jenkins pipeline: groovy libraries plugin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Jenkins Project / Jenkins Pipeline: Groovy Libraries Plugin
0 โ‰ค 797.v90ea_a_9b_e45a_0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
jenkins.io: https://www.jenkins.io/security/advisory/2026-05-27/#SECURITY-3727