CVE-2026-48921
published 2026-05-27CVE-2026-48921: Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to…
PriorityP350high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
0.30%
22.1th percentile
Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | active_directory | — | — |
| jenkins | active_directory_plugin | — | — |
| jenkins | appspider | — | — |
| jenkins | appspider_plugin | — | — |
| jenkins | bitbucket_oauth | — | — |
| jenkins | bitbucket_oauth_plugin | — | — |
| jenkins | credentials_binding | — | — |
| jenkins | credentials_binding_plugin | — | — |
| jenkins | email_extension | — | — |
| jenkins | email_extension_plugin | — | — |
| jenkins | github_integration | — | — |
| jenkins | github_integration_plugin | — | — |
| jenkins | groovy_libraries | — | — |
| jenkins | groovy_libraries_plugin | — | — |
| jenkins | job_import | — | — |
| jenkins | job_import_plugin | — | — |
| jenkins | ldap | — | — |
| jenkins | ldap_plugin | — | — |
| jenkins | ldap_referrals_in_active_directory | — | — |
| jenkins | ldap_referrals_in_active_directory_plugin | — | — |
| jenkins | multijob | — | — |
| jenkins | multijob_plugin | — | — |
| jenkins | pipeline | < 798.v5cc688825312 | 798.v5cc688825312 |
| jenkins_project | jenkins_pipeline_groovy_libraries_plugin | <= 797.v90ea_a_9b_e45a_0 | — |
| ocp-tools-4 | jenkins-rhel8 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Groovy Libraries Plugin up to 797.v90ea_a_9b_e45a_0 on Jenkins Symbolic Links information disclosure (EUVD-2026-32512)
vuldb·2026-05-28·CVSS 7.5
CVE-2026-48921 [HIGH] Groovy Libraries Plugin up to 797.v90ea_a_9b_e45a_0 on Jenkins Symbolic Links information disclosure (EUVD-2026-32512)
A vulnerability classified as problematic was found in Groovy Libraries Plugin up to 797.v90ea_a_9b_e45a_0 on Jenkins. This impacts an unknown function of the component Symbolic Links Handler. The manipulation results in information disclosure.
This vulnerability was named CVE-2026-48921. The attack needs to be approached within the local network. There is no available exploit.
GHSA
Jenkins Pipeline: Groovy Libraries Plugin does not prohibit symbolic links in shared libraries
ghsa·2026-05-27
CVE-2026-48921 [HIGH] CWE-59 Jenkins Pipeline: Groovy Libraries Plugin does not prohibit symbolic links in shared libraries
Jenkins Pipeline: Groovy Libraries Plugin does not prohibit symbolic links in shared libraries
Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries.
This allows attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.
Pipeline: Groovy Libraries Plugin 798.v5cc688825312 prohibits symbolic links in shared libraries.
GHSA
GHSA-qjq3-wqj5-g37q: Jenkins Pipeline: Groovy Libraries Plugin 797
ghsa_unreviewed·2026-05-27
CVE-2026-48921 [HIGH] CWE-59 GHSA-qjq3-wqj5-g37q: Jenkins Pipeline: Groovy Libraries Plugin 797
Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.
Red Hat
pipeline-groovy-lib: Jenkins Pipeline Groovy Libraries Plugin: Information disclosure via symbolic links in shared libraries
vendor_redhat·2026-05-27·CVSS 7.5
CVE-2026-48921 [HIGH] CWE-59 pipeline-groovy-lib: Jenkins Pipeline Groovy Libraries Plugin: Information disclosure via symbolic links in shared libraries
pipeline-groovy-lib: Jenkins Pipeline Groovy Libraries Plugin: Information disclosure via symbolic links in shared libraries
Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.
A flaw was found in the Jenkins Pipeline: Groovy Libraries Plugin. This vulnerability allows an attacker, who can control the content of a library used by a Pipeline job, to read arbitrary files from the Jenkins controller filesystem. This could lead to the disclosure of sensitive information.
Package: jenkins-2-plugins (OpenShift Developer Tools and Services) - Fix deferred
Package: ocp-tools
Jenkins
Jenkins Security Advisory 2026-05-27
vendor_jenkins·2026-05-27·CVSS 6.6
CVE-2026-48916 [MEDIUM] Jenkins Security Advisory 2026-05-27
Title: Jenkins Security Advisory 2026-05-27
Jenkins Security Advisory 2026-05-27
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Active Directory
Plugin
AppSpider
Plugin
Bitbucket OAuth
Plugin
buildgraph-view
Plugin
Credentials Binding
Plugin
Email Extension
Plugin
GitHub Integration
Plugin
No detection rules found.
No public exploits indexed.
2026-05-27
Published