Jenkins exposes other users' timezone and view names to users with Overall/Read permission
Research is free — Hunters explains how the bug works, the root-cause code pattern, how the fix addresses it, and how to test whether a target is affected, in chat. Investigate & write exploit is a paid run — the engine reads the advisory and fix commits, then builds and validates a working proof-of-concept exploit with reproduction steps.
Affected versions
0 → fixed in 2.555.32.556 → fixed in 2.568
Details
Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other users' configured timezone and to enumerate view names of other users' "My Views".
The fix
No fix commit could be resolved for this advisory (it may reference an issue tracker or a non-GitHub patch). See the references below.
References
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2026-53439
- WEBhttps://github.com/jenkinsci/jenkins/commit/0586de425598497cfb4dcdafa5007e507a440a77
- WEBhttps://github.com/jenkinsci/jenkins/commit/98fe05f1753f664ffddd295a03492684b74e1950
- PACKAGEhttps://github.com/jenkinsci/jenkins
- WEBhttps://www.jenkins.io/security/advisory/2026-06-10/#SECURITY-3713