Looking for the vulnerability index of Invicti's legacy products?
Jenkins URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2026-53440) - Vulnerability Database

Jenkins URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2026-53440)

Description

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.

References