← Vulnerability feed

Vulnerability record · CVE-2016-0792 · published 7 April 2016

CVE-2016-0792: Jenkins XStream Deserialization RCE via API Endpoints

Jenkins · Jenkins

Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 accept serialized data in an XML file and deserialize it through XStream, including groovy.util.Expando, without adequate input validation. An authenticated user can supply crafted serialized content that results in arbitrary code execution on the Jenkins controller. The flaw matters because Jenkins is a high-value build system, and code execution there can compromise credentials, source code and downstream artifacts.

8.8 CVSS 3.0 High EPSS 83% · top 0.3% CWE-20 · Improper input validation
8.8CVSS 3.0 base score, v2 9.0
83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and groovy.util.Expando.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRemote code execution on a widely deployed CI server with a very high EPSS score and public exploit references, though it requires an authenticated account.

What it is

Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 accept serialized data in an XML file and deserialize it through XStream, including groovy.util.Expando, without adequate input validation. An authenticated user can supply crafted serialized content that results in arbitrary code execution on the Jenkins controller. The flaw matters because Jenkins is a high-value build system, and code execution there can compromise credentials, source code and downstream artifacts.

Impact

An attacker with a valid Jenkins account gains remote code execution with the privileges of the Jenkins process, allowing full control of the controller and access to stored secrets, jobs and connected agents.

Attack surface

Reachable over the network through Jenkins API endpoints that process XML containing serialized data; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N), so any authenticated user can attempt it.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high (0.833, 99.7th percentile) and public references include an Exploit-tagged writeup plus two Exploit-DB entries, indicating public exploit material exists.

What to do

  • Upgrade Jenkins to 1.650 or later, or LTS to 1.642.2 or later, and apply the vendor security advisory fixes.
  • Apply the referenced Red Hat errata (RHSA-2016:0711, RHSA-2016-1773) for affected OpenShift/Jenkins packages.
  • Restrict and audit who holds Jenkins accounts, since exploitation requires authentication; remove unused accounts and enforce least privilege.
  • Where immediate upgrade is not possible, limit network exposure of Jenkins API endpoints to trusted networks and monitor for anomalous XML submissions.

Detection

  • Review Jenkins access logs for POST/PUT requests to API endpoints carrying XML bodies, especially from accounts that do not normally use the API.
  • Search for XML payloads containing XStream or groovy.util.Expando class references in request bodies or captured traffic.
  • Monitor Jenkins controller processes for unexpected child processes or outbound connections that would indicate post-exploitation code execution.
  • Alert on new or modified Jenkins jobs, credentials or plugins following API activity from unusual source addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-0792 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-23897Jenkins CLI parser arbitrary file read via @ path expansionJenkins 2.441 and earlier, and LTS 2.426.2 and earlier, fails to disable a CLI command parser feature that replaces an '@' character followed by a fi…KEVEPSS 100%analysed9.8CVE-2018-1000861Jenkins Stapler framework URL routing allows remote code executionThe Stapler web framework in Jenkins 2.153 and earlier and LTS 2.138.3 and earlier lets attackers invoke unintended Java methods by requesting crafte…KEVEPSS 98%analysed9.8CVE-2017-1000353Jenkins CLI Java deserialization allows unauthenticated remote code executionJenkins 2.56 and earlier, and 2.46.1 LTS and earlier, deserialize attacker-supplied Java SignedObject data sent to the Jenkins CLI, bypassing the exi…KEVEPSS 100%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed7.5CVE-2015-5317Jenkins Fingerprints pages expose job and build namesJenkins before 1.638 and LTS before 1.625.2 expose sensitive job and build name information through the Fingerprints pages when requested directly. T…KEVEPSS 23%analysed10.0CVE-2014-3496Redhat openshift code injection vulnerabilitycartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 through 2.1.1 allows remote attackers to execute arbitrary commands via shell metach…EPSS 5.1%9.8CVE-2021-21690Jenkins path traversal vulnerabilityAgent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins 2.318 and earlier, …EPSS 2.5%9.8CVE-2021-21691Jenkins link following vulnerabilityCreating symbolic links is possible without the 'symlink' agent-to-controller access control permission in Jenkins 2.318 and earlier, LTS 2.303.2 and…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2016-0792), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.