PT-2026-26074 · Cloudbees+2 · Jenkins+1
Babaucafor
·
Published
2026-03-18
·
Updated
2026-05-24
·
CVE-2026-33002
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Jenkins versions 2.442 through 2.554
Jenkins LTS versions 2.426.3 through 2.541.2
Description
The software does not properly validate the origin of requests made through the CLI WebSocket endpoint. It calculates the expected origin using the Host or X-Forwarded-Host HTTP request headers, which can be exploited through DNS rebinding attacks to bypass origin validation.
Recommendations
Update to a newer version than 2.554.
Update to a newer LTS version than 2.541.2.
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Red Os