{"id":"CVE-2026-53441","title":"Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the `POST config.xml` API, resulting in a store…","summary":"Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the `POST config.xml` API, resulting in a store…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79","CWE-79"],"vendor":"jenkins","product":"jenkins","affected":["jenkins >= 2.483, < 2.568","jenkins >= 2.492.1, < 2.555.3"],"patched":["jenkins 2.555.3"],"published":"2026-06-10","updated":"2026-07-06","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-53441","references":[{"url":"https://www.jenkins.io/security/advisory/2026-06-10/#SECURITY-3731","label":"jenkinsci-cert@googlegroups.com"}],"tags":["nvd"],"epss":0.00261,"epssPercentile":0.18165,"ingestedAt":"2026-07-06T17:44:51.186Z","slug":"CVE-2026-53441","body":"## Overview\n\nJenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the `POST config.xml` API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.\n\n## Affected\n\n- `jenkins >= 2.483, < 2.568`\n- `jenkins >= 2.492.1, < 2.555.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `jenkins 2.555.3`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}