Security Flaw in Jenkins Pipeline: Groovy Libraries Plugin by Jenkins
CVE-2026-48921

7.5HIGH

What is CVE-2026-48921?

The Jenkins Pipeline: Groovy Libraries Plugin version 797.v90ea_a_9b_e45a_0 and earlier is susceptible to a vulnerability due to its failure to restrict symbolic links in shared libraries. This opens a pathway for attackers, who can manipulate the content of a library utilized by a Pipeline job, thus gaining unauthorized access to arbitrary files located on the Jenkins controller's filesystem. This risk underscores the importance of proper permission and security configurations within Jenkins environments.

Affected Version(s)

Jenkins Pipeline: Groovy Libraries Plugin 0 <= 797.v90ea_a_9b_e45a_0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.