CVE-2026-48920

8.8

Jenkins · Email Extension Plugin

The Jenkins Email Extension Plugin contains a vulnerability in versions up to 1933.v45cec755423f that may allow an authenticated attacker to compromise the integrity and availability of the system.

Executive summary

An authenticated attacker can leverage a vulnerability in the Jenkins Email Extension Plugin to achieve full system impact, necessitating an immediate update.

Vulnerability

This vulnerability involves a flaw in the plugin that can be triggered by an attacker with low-level privileges (PR:L). It allows for potential unauthorized actions, as indicated by the CVSS vector's high impact ratings for Confidentiality, Integrity, and Availability.

Business impact

The CVSS score of 8.8 reflects a High severity due to the potential for total system compromise by an authenticated user. Unauthorized access or manipulation of email notifications within a CI/CD pipeline could lead to data exfiltration, the injection of malicious code into deployment workflows, or critical service disruption.

Remediation

Immediate Action: Update the Jenkins Email Extension Plugin to version 1933.1935.v276319e3cc47 or later.

Proactive Monitoring: Review Jenkins access logs for unusual activity originating from low-privilege accounts and monitor email configuration changes.

Compensating Controls: Restrict permissions for plugin management and configuration to a strictly limited set of administrative users until the update is applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for complete system impact, administrators should prioritize the update to version 1933.1935.v276319e3cc47. Ensuring that all plugins are kept up to date is essential to maintaining the security posture of the Jenkins environment.

More Jenkins CVEs