CyberRota
← Ana sayfaya dön

CVE-2026-48920

HIGH · CVSS 8.8 EPSS %0.30

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-05-27T15:16:31.647 · Çekilme zamanı: 2026-06-25T12:11:48.993769+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-48920
Severity
HIGH
CVSS
8.8
EPSS
%0.30
Jenkins

Orijinal NVD Açıklaması

Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem.