← Vulnerability feed

Vulnerability record · CVE-2026-48921 · published 27 May 2026

CVE-2026-48921: Jenkins pipeline\ link following vulnerability

Jenkins · Pipeline\

Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.

7.5 CVSS 3.1 High EPSS 0.43% · top 64.8% CWE-59 · Link following
7.5CVSS 3.1 base score
0.43%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-48921 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2019-1003030Jenkins Pipeline Groovy Plugin sandbox bypass allows arbitrary code executionThe Jenkins Pipeline: Groovy Plugin (2.63 and earlier) contains a sandbox bypass in CpsGroovyShell.java. Attackers who can control pipeline scripts c…KEVEPSS 97%analysed9.9CVE-2022-43402Jenkins pipeline\ vulnerabilityA sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Pipeline: Groovy Plugin 2802.v5…EPSS 1.3%9.8CVE-2019-1003041Jenkins pipeline\ vulnerabilityA sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sandboxed scr…EPSS 3.4%8.8CVE-2022-43407Jenkins pipeline\ cross-site request forgery vulnerabilityJenkins Pipeline: Input Step Plugin 451.vf1a_a_4f405289 and earlier does not restrict or sanitize the optionally specified ID of the 'input' step, wh…EPSS 0.53%8.8CVE-2022-25181Jenkins pipeline\ vulnerabilityA sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure…EPSS 1.6%8.8CVE-2022-25182Jenkins pipeline\ vulnerabilityA sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure…EPSS 1.6%8.8CVE-2022-25183Jenkins pipeline\ vulnerabilityJenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to create cache directories witho…EPSS 1.6%8.8CVE-2022-25173Jenkins pipeline\ os command injection vulnerabilityJenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typ…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2026-48921), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.