cbcvebase.
CVE-2026-48920
published 2026-05-27

CVE-2026-48920: Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem.

Affected

25 ranges
VendorProductVersion rangeFixed in
jenkinsactive_directory
jenkinsactive_directory_plugin
jenkinsappspider
jenkinsappspider_plugin
jenkinsbitbucket_oauth
jenkinsbitbucket_oauth_plugin
jenkinscredentials_binding
jenkinscredentials_binding_plugin
jenkinsemail_extension<= 1925.v1598902b_58dd
jenkinsemail_extension
jenkinsemail_extension
jenkinsemail_extension_plugin
jenkinsgithub_integration
jenkinsgithub_integration_plugin
jenkinsgroovy_libraries
jenkinsgroovy_libraries_plugin
jenkinsjob_import
jenkinsjob_import_plugin
jenkinsldap
jenkinsldap_plugin
jenkinsldap_referrals_in_active_directory
jenkinsldap_referrals_in_active_directory_plugin
jenkinsmultijob
jenkinsmultijob_plugin
jenkins_projectjenkins_email_extension_plugin<= 1933.v45cec755423f