Executive brief
Jenkins, a popular automation server used for continuous integration and deployment, contains authorization bypass flaws that allow users with basic read permissions to discover other users' timezone settings and enumerate private views. An attacker with minimal privileges can exploit this to gather information about other users and their Jenkins configurations, potentially facilitating social engineering or further attacks.
Technical details
This vulnerability (SECURITY-3713 / CVE-2026-53439) results from missing authorization checks in HTTP endpoints exposed by Jenkins core. An attacker with Overall/Read permission (the minimal Jenkins privilege level) can access endpoints that return sensitive user profile information without performing additional permission validation. Specifically, the affected endpoints leak (1) timezone configuration for arbitrary users and (2) view names from other users' private "My Views" collections. The root cause is the absence of permission checks before returning this user profile data; the fix adds explicit permission checks (e.g., Jenkins.ADMINISTER or user identity verification) before serving this information. The attack requires network access to Jenkins and at least Overall/Read permission, but no additional user interaction or privileges. Patches are available in Jenkins 2.568 and LTS 2.555.3, which enforce proper authorization checks in the affected endpoints.
Affected products
- Jenkins Jenkins 2.567 and earlier, LTS 2.555.2 and earlier
- Jenkins jenkins-core < 2.555.3 and >= 2.556, < 2.568
Timeline
- 2026-06-10: disclosed: Jenkins Security Advisory published; CVE-2026-53439 assigned
- 2026-06-10: patched: Patches released in Jenkins 2.568 and LTS 2.555.3