Vulnerability record · CVE-2016-0792 · published 7 April 2016
CVE-2016-0792: Jenkins XStream Deserialization RCE via API Endpoints
Jenkins · Jenkins
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 accept serialized data in an XML file and deserialize it through XStream, including groovy.util.Expando, without adequate input validation. An authenticated user can supply crafted serialized content that results in arbitrary code execution on the Jenkins controller. The flaw matters because Jenkins is a high-value build system, and code execution there can compromise credentials, source code and downstream artifacts.
Description
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and groovy.util.Expando.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution on a widely deployed CI server with a very high EPSS score and public exploit references, though it requires an authenticated account.
What it is
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 accept serialized data in an XML file and deserialize it through XStream, including groovy.util.Expando, without adequate input validation. An authenticated user can supply crafted serialized content that results in arbitrary code execution on the Jenkins controller. The flaw matters because Jenkins is a high-value build system, and code execution there can compromise credentials, source code and downstream artifacts.
Impact
An attacker with a valid Jenkins account gains remote code execution with the privileges of the Jenkins process, allowing full control of the controller and access to stored secrets, jobs and connected agents.
Attack surface
Reachable over the network through Jenkins API endpoints that process XML containing serialized data; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N), so any authenticated user can attempt it.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.833, 99.7th percentile) and public references include an Exploit-tagged writeup plus two Exploit-DB entries, indicating public exploit material exists.
What to do
- Upgrade Jenkins to 1.650 or later, or LTS to 1.642.2 or later, and apply the vendor security advisory fixes.
- Apply the referenced Red Hat errata (RHSA-2016:0711, RHSA-2016-1773) for affected OpenShift/Jenkins packages.
- Restrict and audit who holds Jenkins accounts, since exploitation requires authentication; remove unused accounts and enforce least privilege.
- Where immediate upgrade is not possible, limit network exposure of Jenkins API endpoints to trusted networks and monitor for anomalous XML submissions.
Detection
- Review Jenkins access logs for POST/PUT requests to API endpoints carrying XML bodies, especially from accounts that do not normally use the API.
- Search for XML payloads containing XStream or groovy.util.Expando class references in request bodies or captured traffic.
- Monitor Jenkins controller processes for unexpected child processes or outbound connections that would indicate post-exploitation code execution.
- Alert on new or modified Jenkins jobs, credentials or plugins following API activity from unusual source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-0792 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-0792), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.