Security Flaw in Jenkins Pipeline: Groovy Libraries Plugin by Jenkins
CVE-2026-48921
7.5HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 27 May 2026
What is CVE-2026-48921?
The Jenkins Pipeline: Groovy Libraries Plugin version 797.v90ea_a_9b_e45a_0 and earlier is susceptible to a vulnerability due to its failure to restrict symbolic links in shared libraries. This opens a pathway for attackers, who can manipulate the content of a library utilized by a Pipeline job, thus gaining unauthorized access to arbitrary files located on the Jenkins controller's filesystem. This risk underscores the importance of proper permission and security configurations within Jenkins environments.
Affected Version(s)
Jenkins Pipeline: Groovy Libraries Plugin 0 <= 797.v90ea_a_9b_e45a_0