Jenkins Continuous Integration Engine
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Jenkins.
Recent Jenkins Security Advisories
| Advisory | Title | Published |
|---|---|---|
| 2026-09-02 | Jenkins Security Advisory 2026-09-02 | September 2, 2026 |
| 2026-08-05 | Jenkins Security Advisory 2026-08-05 | August 5, 2026 |
| 2026-06-24 | Jenkins Security Advisory 2026-06-24 | June 24, 2026 |
| 2026-06-10 | Jenkins Security Advisory 2026-06-10 | June 10, 2026 |
| 2026-05-27 | Jenkins Security Advisory 2026-05-27 | May 27, 2026 |
| 2026-04-29 | Jenkins Security Advisory 2026-04-29 | April 29, 2026 |
| 2026-03-18 | Jenkins Security Advisory 2026-03-18 | March 18, 2026 |
| 2026-02-18 | Jenkins Security Advisory 2026-02-18 | February 18, 2026 |
| 2025-12-10 | Jenkins Security Advisory 2025-12-10 | December 10, 2025 |
| 2025-10-29 | Jenkins Security Advisory 2025-10-29 | October 29, 2025 |
Known Exploited Jenkins Vulnerabilities
The following Jenkins vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Jenkins Remote Code Execution Vulnerability |
Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would be deserialized using a new ObjectInputStream, bypassing the existing blocklist-based protection mechanism. CVE-2017-1000353 Exploit Probability: 99.7% |
October 2, 2025 |
The vulnerability CVE-2017-1000353: Jenkins Remote Code Execution Vulnerability is in the top 1% of the currently known exploitable vulnerabilities.
Jenkins EOL Dates
Ensure that you are using a supported version of Jenkins. Here are some end of life, and end of support dates for Jenkins.
| Release | EOL Date | Status |
|---|---|---|
| 2.568 | - |
Active
|
| 2.555 | June 10, 2026 |
EOL
Jenkins 2.555 became EOL in 2026. |
| 2.541 | April 15, 2026 |
EOL
Jenkins 2.541 became EOL in 2026. |
| 2.528 | January 21, 2026 |
EOL
Jenkins 2.528 became EOL in 2026. |
| 2.516 | October 15, 2025 |
EOL
Jenkins 2.516 became EOL in 2025. |
| 2.504 | July 23, 2025 |
EOL
Jenkins 2.504 became EOL in 2025. |
| 2.492 | April 30, 2025 |
EOL
Jenkins 2.492 became EOL in 2025. |
| 2.479 | February 5, 2025 |
EOL
Jenkins 2.479 became EOL in 2025. |
| 2.462 | October 2, 2024 |
EOL
Jenkins 2.462 became EOL in 2024. |
| 2.452 | August 7, 2024 |
EOL
Jenkins 2.452 became EOL in 2024. |
| 2.440 | May 15, 2024 |
EOL
Jenkins 2.440 became EOL in 2024. |
| 2.426 | February 21, 2024 |
EOL
Jenkins 2.426 became EOL in 2024. |
| 2.414 | November 15, 2023 |
EOL
Jenkins 2.414 became EOL in 2023. |
| 2.401 | August 23, 2023 |
EOL
Jenkins 2.401 became EOL in 2023. |
| 2.387 | May 31, 2023 |
EOL
Jenkins 2.387 became EOL in 2023. |
| 2.375 | March 8, 2023 |
EOL
Jenkins 2.375 became EOL in 2023. |
| 2.361 | November 30, 2022 |
EOL
Jenkins 2.361 became EOL in 2022. |
| 2.346 | September 7, 2022 |
EOL
Jenkins 2.346 became EOL in 2022. |
| 2 | - |
Active
|
By the Year
In 2026 there have been 118 vulnerabilities in Jenkins with an average score of 5.8 out of ten. Last year, in 2025 Jenkins had 75 security vulnerabilities published. That is, 43 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.32.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 118 | 5.83 |
| 2025 | 75 | 5.51 |
| 2024 | 7 | 7.05 |
| 2023 | 16 | 6.79 |
| 2022 | 12 | 6.18 |
| 2021 | 29 | 7.37 |
| 2020 | 20 | 5.64 |
| 2019 | 25 | 6.21 |
| 2018 | 31 | 5.86 |
It may take a day or so for new Jenkins vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Jenkins Security Vulnerabilities
Jenkins Param Remote Trigger Plugin <=3.2.2 Exposes Unencrypted Tokens
CVE-2026-84676
4.3 - Medium
- September 02, 2026
Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
Missing Encryption of Sensitive Data
Jenkins TICS Plugin OS Command Injection via Build Env (before 2025.1.1)
CVE-2026-84675
7.4 - High
- September 02, 2026
OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build.
Shell injection
Jenkins XebiaLabs XL Deploy Plugin 26.1.0 Missing Permission Checks
CVE-2026-84674
5.4 - Medium
- September 02, 2026
Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
AuthZ
Jenkins Customizable Header Plugin XSS via Stapler Data Binding
CVE-2026-84673
8.8 - High
- September 02, 2026
Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance configuration through Stapler data binding, allowing attackers to configure a custom SVG icon containing inline JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability.
XSS
Jenkins Entra Plugin Group DN Collision Grants Privileged Access
CVE-2026-84672
8.8 - High
- September 02, 2026
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group.
Insecure Direct Object Reference / IDOR
Jenkins FP Plugin Arbitrary File Write via Stapler Binding
CVE-2026-84671
8.8 - High
- September 02, 2026
Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system through Stapler data binding, which can lead to remote code execution.
Directory traversal
Jenkins Perf. Plugin RCE via unrestricted deserialization
CVE-2026-84670
8.8 - High
- September 02, 2026
Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.
Marshaling, Unmarshaling
Jenkins Allure Plugin <=2.35.2 Path Traversal (CVE-2026-84669)
CVE-2026-84669
8.8 - High
- September 02, 2026
A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permission on jobs that publish Allure report results to read arbitrary files on the Jenkins controller's file system.
Directory traversal
Jenkins SAML Plugin <=4.618: Metadata file overwrite via Stapler
CVE-2026-84668
8.8 - High
- September 02, 2026
Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled content and authenticate as any user.
Authorization
Jenkins ThinBackup Plugin <2.1.4: Config Overwrite via Stapler
CVE-2026-84667
7.1 - High
- September 02, 2026
Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapler data binding, allowing attackers to redirect backup writes to an attacker-specified directory and to include arbitrary files from the Jenkins controller file system in backups.
Directory traversal
Jenkins Job Config History Plugin: Overwrite Config via Stapler Data Binding
CVE-2026-84666
5.4 - Medium
- September 02, 2026
Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration through Stapler data binding, allowing attackers to redirect history storage to an attacker-specified directory and modify history recording settings.
Improper Input Validation
Stored XSS via javascript: in Jenkins SonarQube Scanner Plugin <=2.18.3
CVE-2026-84665
8 - High
- September 02, 2026
Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
XSS
Jenkins GitLab Plugin <=1.9.16 Global Config Overwrite via Stapler Data Binding
CVE-2026-84664
5.4 - Medium
- September 02, 2026
Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowing attackers to connect to an attacker-specified URL using GitLab API tokens already configured by administrators.
Download of Code Without Integrity Check
CSRF in Jenkins Pipeline Groovy Libraries Plugin deletes shared library caches
CVE-2026-84663
5.4 - Medium
- September 02, 2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 798.v5cc688825312 and earlier allows attackers to delete shared library caches.
Session Riding
Jenkins LDAP Plugin <=807.809: URL Connect via Stapler Data Binding
CVE-2026-84662
4.3 - Medium
- September 02, 2026
Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler data binding, allowing attackers to connect to an attacker-specified URL.
Open Redirect
Jenkins Build Step Plugin: propagateAbort Permission Check Bypass
CVE-2026-84661
5.4 - Medium
- September 02, 2026
A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds awaited by the `waitForBuild` step when the `propagateAbort` parameter is used to be canceled even when the build's authentication lacks Item/Cancel permission on the downstream job.
AuthZ
Jenkins Pipeline Build Step Plugin Missing Permission Check
CVE-2026-84660
5.4 - Medium
- September 02, 2026
A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds triggered by the `build` step to be canceled even when the build's authentication lacks Item/Cancel permission on the downstream job.
AuthZ
Jenkins ScriptSec Plugin: sandbox bypass via missing permission check
CVE-2026-84659
4.3 - Medium
- September 02, 2026
Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, allowing attackers to disable it through Stapler data binding.
AuthZ
Jenkins Script Security Plugin @DataBoundConstructor config read vulnerability
CVE-2026-84658
4.3 - Medium
- September 02, 2026
Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowing attackers able to submit certain forms to read that configuration.
Information Disclosure
Jenkins 2.579 LTS: Build CLI -s Bypasses Item/Cancel Perm (CVE-2026-84657)
CVE-2026-84657
4.2 - Medium
- September 02, 2026
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permission to cancel builds started by other users.
AuthZ
Missing Permission Check in Jenkins 2.579/LTS 2.568.2: Unauthorized Job Parameter View
CVE-2026-84656
4.3 - Medium
- September 02, 2026
A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter names and values of jobs they have no access to.
AuthZ
Jenkins <=2.579 LTS <=2.568.2 JSON Map Key Injection via REST API
CVE-2026-84655
4.3 - Medium
- September 02, 2026
Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API responses.
Output Sanitization
Jenkins Stapler <2107 (except 2088.2093) allows global config via form
CVE-2026-84654
5.4 - Medium
- September 02, 2026
In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, form data binding allows setting public static fields of the bound configuration object, allowing attackers who can submit configuration forms to modify public static fields of the configuration objects those forms are bound to, resulting in changes that apply globally to the Jenkins instance.
Assumed-Immutable Parameter Tampering
Jenkins Session Fixation via RememberMe Cookie (up to 2.579)
CVE-2026-84652
7.3 - High
- September 02, 2026
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known session cookie in the victim's browser, which after the victim authenticates via the "remember me" cookie, grants the attacker access to Jenkins as that user.
Session Fixation
Jenkins 2.421-2.579 LTS 2.426.1-2.568.2: Overall/Manage Can Alter Appearance Config
CVE-2026-84653
3.5 - Low
- September 02, 2026
Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.
AuthZ
Jenkins API Agent Config Overwrite CVE-2026-84651 (2.579, 2.568.2)
CVE-2026-84651
6.3 - Medium
- September 02, 2026
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by specifying that agent's name in the submitted XML document, allowing attackers with Agent/Configure permission on one agent to take over a different agent, gaining control of its configuration and obtaining access to its inbound agent secret and environment variables.
Authorization
Jenkins 2.579 & LTS 2.568.2 Transient Field Deserialization Weakness
CVE-2026-84650
8.8 - High
- September 02, 2026
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used.
Authorization Bypass Through User-Controlled SQL Primary Key
Jenkins Stapler CSRF Token Leak 2.447-2.579 via SameSite JS
CVE-2026-84649
8.8 - High
- September 02, 2026
In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resources embeds the user's cross-site request forgery (CSRF) token (crumb) as a string literal, allowing attackers with control over a page hosted on the same site as Jenkins to obtain a valid crumb for the targeted user's session and perform actions on their behalf.
Session Riding
Jenkins System Log Viewer XSS before 2.579 / LTS 2.568.2
CVE-2026-84648
8.8 - High
- September 02, 2026
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in control of agent processes.
XSS
Stapler Unrestricted Object Instantiation via Form Binding in Jenkins <2.579
CVE-2026-84647
8.8 - High
- September 02, 2026
In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field type, allowing attackers with Overall/Read permission to instantiate types related to configuration for which that field type was not intended.
Marshaling, Unmarshaling
Jenkins 2.579-: XML Deserialization permits Nested User Objects with Overall/Read
CVE-2026-84646
4.3 - Medium
- September 02, 2026
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.
Marshaling, Unmarshaling
Jenkins 2.579/LTS 2.568.2 RCE via Stapler in config.xml (nested objects)
CVE-2026-84645
8.8 - High
- September 02, 2026
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field values in user-submitted `config.xml` documents and subsequently handle HTTP requests via Stapler, resulting in remote code execution.
Code Injection
Jenkins <=2.555.3 TAR Symlink PT - Arbitrary File Disclosure
CVE-2026-19429
- August 10, 2026
XXE in Jenkins Ivy Report Plugin v1.2 or earlier
CVE-2026-70448
7.1 - High
- August 05, 2026
Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files.
XXE
Jenkins AWS CodeBuild Plugin 0.59: No Permission Check, Credential ID Leak
CVE-2026-70447
4.3 - Medium
- August 05, 2026
Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
AuthZ
Jenkins CodeSonar Plugin <3.6.0: Permission Gap Enumerates Credentials IDs
CVE-2026-70446
4.3 - Medium
- August 05, 2026
Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
AuthZ
Missing Permission Checks in Jenkins Sauce OnDemand Plugin 2.2.0 (ID Enumeration)
CVE-2026-70445
4.3 - Medium
- August 05, 2026
Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
AuthZ
Jenkins Violation Comments to GitLab <=2.62.0: Missing Permission Check
CVE-2026-70444
4.3 - Medium
- August 05, 2026
A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Protection Mechanism Failure
Jenkins Horreum Plugin <0.16.162> CVE-2026-70443: Credentials Leakage
CVE-2026-70443
4.3 - Medium
- August 05, 2026
Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to have Jenkins send credentials they are not entitled to use to the administrator-configured Horreum URL.
Improper Privilege Management
CVE-2026-70442: Jenkins GChat Plugin Exposes Unauthorized Credentials
CVE-2026-70442
4.3 - Medium
- August 05, 2026
Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to use.
AuthZ
Jenkins Display Plugin <1.15 XSS via unescaped job name in JS context
CVE-2026-70441
5.4 - Medium
- August 05, 2026
Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Create or Item/Configure permission.
XSS
Jenkins Qualys Container Scanning Plugin 1.8.0.5 XSS Vulnerability
CVE-2026-70440
5.4 - Medium
- August 05, 2026
Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a JavaScript context, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
XSS
Jenkins XML Job to Job DSL Plugin before 0.1.13: Unchecked Permission Elevation
CVE-2026-70439
6.5 - Medium
- August 05, 2026
Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appropriate permissions to invoke the conversion functionality.
AuthZ
Jenkins PRTP <=3.2.2 Cred-ID Enumeration Due to Missing Permission Check
CVE-2026-70438
4.3 - Medium
- August 05, 2026
A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
AuthZ
CVE-2026-70437 Jenkins Webhook Plugin Timing Attack on Bearer Token
CVE-2026-70437
3.7 - Low
- August 05, 2026
Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token.
Observable Timing Discrepancy
Jenkins External Workspace Manager Plugin 1.4.1: Insufficient Permission Check
CVE-2026-70436
4.3 - Medium
- August 05, 2026
Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with Overall/Read permission to read files in workspaces they are not authorized to access.
AuthZ
Credential Leak in Jenkins SCM-Manager Plugin <=1.11.1 via Missing Permission Check
CVE-2026-70435
4.2 - Medium
- August 05, 2026
A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
AuthZ
Jenkins SCM-Manager Plugin <1.11.1: CSRF credential leak
CVE-2026-70434
4.2 - Medium
- August 05, 2026
A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Session Riding
Jenkins HCL AppScan Plugin 1.8.3 No Permission to Enumerate Credential IDs
CVE-2026-70433
4.3 - Medium
- August 05, 2026
Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
AuthZ
CVE-2026-70432: CSRF in Jenkins Multijob Plugin v<669> Enables RCE
CVE-2026-70432
8.8 - High
- August 05, 2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM.
Session Riding