PT-2026-44013 · Jenkins · Email Extension Plugin

Published

2026-05-27

·

Updated

2026-05-28

·

CVE-2026-48920

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Email Extension Plugin versions prior to 1933.v45cec755423f
Description The plugin allows inlining images as base64 in email content by setting the data-inline attribute. Because there are no restrictions on the image URLs that can be inlined, attackers who can control the email content can specify file: URLs for images to read arbitrary files from the Jenkins controller filesystem.
Recommendations Update to a version later than 1933.v45cec755423f.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-48920

Affected Products

Email Extension Plugin