cbcvebase.
CVE-2026-48921
published 2026-05-27

CVE-2026-48921: Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to…

PriorityP350high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
0.30%
22.1th percentile
Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
jenkinsactive_directory
jenkinsactive_directory_plugin
jenkinsappspider
jenkinsappspider_plugin
jenkinsbitbucket_oauth
jenkinsbitbucket_oauth_plugin
jenkinscredentials_binding
jenkinscredentials_binding_plugin
jenkinsemail_extension
jenkinsemail_extension_plugin
jenkinsgithub_integration
jenkinsgithub_integration_plugin
jenkinsgroovy_libraries
jenkinsgroovy_libraries_plugin
jenkinsjob_import
jenkinsjob_import_plugin
jenkinsldap
jenkinsldap_plugin
jenkinsldap_referrals_in_active_directory
jenkinsldap_referrals_in_active_directory_plugin
jenkinsmultijob
jenkinsmultijob_plugin
jenkinspipeline< 798.v5cc688825312798.v5cc688825312
jenkins_projectjenkins_pipeline_groovy_libraries_plugin<= 797.v90ea_a_9b_e45a_0
ocp-tools-4jenkins-rhel8

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.