Jenkins Jenkins Continuous Integration Engine

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Jenkins.

Recent Jenkins Security Advisories

Advisory Title Published
2026-09-02 Jenkins Security Advisory 2026-09-02 September 2, 2026
2026-08-05 Jenkins Security Advisory 2026-08-05 August 5, 2026
2026-06-24 Jenkins Security Advisory 2026-06-24 June 24, 2026
2026-06-10 Jenkins Security Advisory 2026-06-10 June 10, 2026
2026-05-27 Jenkins Security Advisory 2026-05-27 May 27, 2026
2026-04-29 Jenkins Security Advisory 2026-04-29 April 29, 2026
2026-03-18 Jenkins Security Advisory 2026-03-18 March 18, 2026
2026-02-18 Jenkins Security Advisory 2026-02-18 February 18, 2026
2025-12-10 Jenkins Security Advisory 2025-12-10 December 10, 2025
2025-10-29 Jenkins Security Advisory 2025-10-29 October 29, 2025

Known Exploited Jenkins Vulnerabilities

The following Jenkins vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Jenkins Remote Code Execution Vulnerability Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would be deserialized using a new ObjectInputStream, bypassing the existing blocklist-based protection mechanism.
CVE-2017-1000353 Exploit Probability: 99.7%
October 2, 2025

The vulnerability CVE-2017-1000353: Jenkins Remote Code Execution Vulnerability is in the top 1% of the currently known exploitable vulnerabilities.

Jenkins EOL Dates

Ensure that you are using a supported version of Jenkins. Here are some end of life, and end of support dates for Jenkins.

Release EOL Date Status
2.568 -
Active

2.555 June 10, 2026
EOL

Jenkins 2.555 became EOL in 2026.

2.541 April 15, 2026
EOL

Jenkins 2.541 became EOL in 2026.

2.528 January 21, 2026
EOL

Jenkins 2.528 became EOL in 2026.

2.516 October 15, 2025
EOL

Jenkins 2.516 became EOL in 2025.

2.504 July 23, 2025
EOL

Jenkins 2.504 became EOL in 2025.

2.492 April 30, 2025
EOL

Jenkins 2.492 became EOL in 2025.

2.479 February 5, 2025
EOL

Jenkins 2.479 became EOL in 2025.

2.462 October 2, 2024
EOL

Jenkins 2.462 became EOL in 2024.

2.452 August 7, 2024
EOL

Jenkins 2.452 became EOL in 2024.

2.440 May 15, 2024
EOL

Jenkins 2.440 became EOL in 2024.

2.426 February 21, 2024
EOL

Jenkins 2.426 became EOL in 2024.

2.414 November 15, 2023
EOL

Jenkins 2.414 became EOL in 2023.

2.401 August 23, 2023
EOL

Jenkins 2.401 became EOL in 2023.

2.387 May 31, 2023
EOL

Jenkins 2.387 became EOL in 2023.

2.375 March 8, 2023
EOL

Jenkins 2.375 became EOL in 2023.

2.361 November 30, 2022
EOL

Jenkins 2.361 became EOL in 2022.

2.346 September 7, 2022
EOL

Jenkins 2.346 became EOL in 2022.

2 -
Active

By the Year

In 2026 there have been 118 vulnerabilities in Jenkins with an average score of 5.8 out of ten. Last year, in 2025 Jenkins had 75 security vulnerabilities published. That is, 43 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.32.




Year Vulnerabilities Average Score
2026 118 5.83
2025 75 5.51
2024 7 7.05
2023 16 6.79
2022 12 6.18
2021 29 7.37
2020 20 5.64
2019 25 6.21
2018 31 5.86

It may take a day or so for new Jenkins vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Jenkins Security Vulnerabilities

Jenkins Param Remote Trigger Plugin <=3.2.2 Exposes Unencrypted Tokens
CVE-2026-84676 4.3 - Medium - September 02, 2026

Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

Missing Encryption of Sensitive Data

Jenkins TICS Plugin OS Command Injection via Build Env (before 2025.1.1)
CVE-2026-84675 7.4 - High - September 02, 2026

OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build.

Shell injection

Jenkins XebiaLabs XL Deploy Plugin 26.1.0 Missing Permission Checks
CVE-2026-84674 5.4 - Medium - September 02, 2026

Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

AuthZ

Jenkins Customizable Header Plugin XSS via Stapler Data Binding
CVE-2026-84673 8.8 - High - September 02, 2026

Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance configuration through Stapler data binding, allowing attackers to configure a custom SVG icon containing inline JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability.

XSS

Jenkins Entra Plugin Group DN Collision Grants Privileged Access
CVE-2026-84672 8.8 - High - September 02, 2026

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group.

Insecure Direct Object Reference / IDOR

Jenkins FP Plugin Arbitrary File Write via Stapler Binding
CVE-2026-84671 8.8 - High - September 02, 2026

Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system through Stapler data binding, which can lead to remote code execution.

Directory traversal

Jenkins Perf. Plugin RCE via unrestricted deserialization
CVE-2026-84670 8.8 - High - September 02, 2026

Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.

Marshaling, Unmarshaling

Jenkins Allure Plugin <=2.35.2 Path Traversal (CVE-2026-84669)
CVE-2026-84669 8.8 - High - September 02, 2026

A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permission on jobs that publish Allure report results to read arbitrary files on the Jenkins controller's file system.

Directory traversal

Jenkins SAML Plugin <=4.618: Metadata file overwrite via Stapler
CVE-2026-84668 8.8 - High - September 02, 2026

Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled content and authenticate as any user.

Authorization

Jenkins ThinBackup Plugin <2.1.4: Config Overwrite via Stapler
CVE-2026-84667 7.1 - High - September 02, 2026

Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapler data binding, allowing attackers to redirect backup writes to an attacker-specified directory and to include arbitrary files from the Jenkins controller file system in backups.

Directory traversal

Jenkins Job Config History Plugin: Overwrite Config via Stapler Data Binding
CVE-2026-84666 5.4 - Medium - September 02, 2026

Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration through Stapler data binding, allowing attackers to redirect history storage to an attacker-specified directory and modify history recording settings.

Improper Input Validation

Stored XSS via javascript: in Jenkins SonarQube Scanner Plugin <=2.18.3
CVE-2026-84665 8 - High - September 02, 2026

Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

XSS

Jenkins GitLab Plugin <=1.9.16 Global Config Overwrite via Stapler Data Binding
CVE-2026-84664 5.4 - Medium - September 02, 2026

Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowing attackers to connect to an attacker-specified URL using GitLab API tokens already configured by administrators.

Download of Code Without Integrity Check

CSRF in Jenkins Pipeline Groovy Libraries Plugin deletes shared library caches
CVE-2026-84663 5.4 - Medium - September 02, 2026

A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 798.v5cc688825312 and earlier allows attackers to delete shared library caches.

Session Riding

Jenkins LDAP Plugin <=807.809: URL Connect via Stapler Data Binding
CVE-2026-84662 4.3 - Medium - September 02, 2026

Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler data binding, allowing attackers to connect to an attacker-specified URL.

Open Redirect

Jenkins Build Step Plugin: propagateAbort Permission Check Bypass
CVE-2026-84661 5.4 - Medium - September 02, 2026

A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds awaited by the `waitForBuild` step when the `propagateAbort` parameter is used to be canceled even when the build's authentication lacks Item/Cancel permission on the downstream job.

AuthZ

Jenkins Pipeline Build Step Plugin Missing Permission Check
CVE-2026-84660 5.4 - Medium - September 02, 2026

A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds triggered by the `build` step to be canceled even when the build's authentication lacks Item/Cancel permission on the downstream job.

AuthZ

Jenkins ScriptSec Plugin: sandbox bypass via missing permission check
CVE-2026-84659 4.3 - Medium - September 02, 2026

Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, allowing attackers to disable it through Stapler data binding.

AuthZ

Jenkins Script Security Plugin @DataBoundConstructor config read vulnerability
CVE-2026-84658 4.3 - Medium - September 02, 2026

Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowing attackers able to submit certain forms to read that configuration.

Information Disclosure

Jenkins 2.579 LTS: Build CLI -s Bypasses Item/Cancel Perm (CVE-2026-84657)
CVE-2026-84657 4.2 - Medium - September 02, 2026

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permission to cancel builds started by other users.

AuthZ

Missing Permission Check in Jenkins 2.579/LTS 2.568.2: Unauthorized Job Parameter View
CVE-2026-84656 4.3 - Medium - September 02, 2026

A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter names and values of jobs they have no access to.

AuthZ

Jenkins <=2.579 LTS <=2.568.2 JSON Map Key Injection via REST API
CVE-2026-84655 4.3 - Medium - September 02, 2026

Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API responses.

Output Sanitization

Jenkins Stapler <2107 (except 2088.2093) allows global config via form
CVE-2026-84654 5.4 - Medium - September 02, 2026

In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, form data binding allows setting public static fields of the bound configuration object, allowing attackers who can submit configuration forms to modify public static fields of the configuration objects those forms are bound to, resulting in changes that apply globally to the Jenkins instance.

Assumed-Immutable Parameter Tampering

Jenkins Session Fixation via RememberMe Cookie (up to 2.579)
CVE-2026-84652 7.3 - High - September 02, 2026

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known session cookie in the victim's browser, which after the victim authenticates via the "remember me" cookie, grants the attacker access to Jenkins as that user.

Session Fixation

Jenkins 2.421-2.579 LTS 2.426.1-2.568.2: Overall/Manage Can Alter Appearance Config
CVE-2026-84653 3.5 - Low - September 02, 2026

Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.

AuthZ

Jenkins API Agent Config Overwrite CVE-2026-84651 (2.579, 2.568.2)
CVE-2026-84651 6.3 - Medium - September 02, 2026

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by specifying that agent's name in the submitted XML document, allowing attackers with Agent/Configure permission on one agent to take over a different agent, gaining control of its configuration and obtaining access to its inbound agent secret and environment variables.

Authorization

Jenkins 2.579 & LTS 2.568.2 Transient Field Deserialization Weakness
CVE-2026-84650 8.8 - High - September 02, 2026

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used.

Authorization Bypass Through User-Controlled SQL Primary Key

Jenkins Stapler CSRF Token Leak 2.447-2.579 via SameSite JS
CVE-2026-84649 8.8 - High - September 02, 2026

In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resources embeds the user's cross-site request forgery (CSRF) token (crumb) as a string literal, allowing attackers with control over a page hosted on the same site as Jenkins to obtain a valid crumb for the targeted user's session and perform actions on their behalf.

Session Riding

Jenkins System Log Viewer XSS before 2.579 / LTS 2.568.2
CVE-2026-84648 8.8 - High - September 02, 2026

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in control of agent processes.

XSS

Stapler Unrestricted Object Instantiation via Form Binding in Jenkins <2.579
CVE-2026-84647 8.8 - High - September 02, 2026

In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field type, allowing attackers with Overall/Read permission to instantiate types related to configuration for which that field type was not intended.

Marshaling, Unmarshaling

Jenkins 2.579-: XML Deserialization permits Nested User Objects with Overall/Read
CVE-2026-84646 4.3 - Medium - September 02, 2026

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.

Marshaling, Unmarshaling

Jenkins 2.579/LTS 2.568.2 RCE via Stapler in config.xml (nested objects)
CVE-2026-84645 8.8 - High - September 02, 2026

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field values in user-submitted `config.xml` documents and subsequently handle HTTP requests via Stapler, resulting in remote code execution.

Code Injection

XXE in Jenkins Ivy Report Plugin v1.2 or earlier
CVE-2026-70448 7.1 - High - August 05, 2026

Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files.

XXE

Jenkins AWS CodeBuild Plugin 0.59: No Permission Check, Credential ID Leak
CVE-2026-70447 4.3 - Medium - August 05, 2026

Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

AuthZ

Jenkins CodeSonar Plugin <3.6.0: Permission Gap Enumerates Credentials IDs
CVE-2026-70446 4.3 - Medium - August 05, 2026

Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

AuthZ

Missing Permission Checks in Jenkins Sauce OnDemand Plugin 2.2.0 (ID Enumeration)
CVE-2026-70445 4.3 - Medium - August 05, 2026

Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

AuthZ

Jenkins Violation Comments to GitLab <=2.62.0: Missing Permission Check
CVE-2026-70444 4.3 - Medium - August 05, 2026

A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

Protection Mechanism Failure

Jenkins Horreum Plugin <0.16.162> CVE-2026-70443: Credentials Leakage
CVE-2026-70443 4.3 - Medium - August 05, 2026

Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to have Jenkins send credentials they are not entitled to use to the administrator-configured Horreum URL.

Improper Privilege Management

CVE-2026-70442: Jenkins GChat Plugin Exposes Unauthorized Credentials
CVE-2026-70442 4.3 - Medium - August 05, 2026

Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to use.

AuthZ

Jenkins Display Plugin <1.15 XSS via unescaped job name in JS context
CVE-2026-70441 5.4 - Medium - August 05, 2026

Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Create or Item/Configure permission.

XSS

Jenkins Qualys Container Scanning Plugin 1.8.0.5 XSS Vulnerability
CVE-2026-70440 5.4 - Medium - August 05, 2026

Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a JavaScript context, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

XSS

Jenkins XML Job to Job DSL Plugin before 0.1.13: Unchecked Permission Elevation
CVE-2026-70439 6.5 - Medium - August 05, 2026

Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appropriate permissions to invoke the conversion functionality.

AuthZ

Jenkins PRTP <=3.2.2 Cred-ID Enumeration Due to Missing Permission Check
CVE-2026-70438 4.3 - Medium - August 05, 2026

A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

AuthZ

CVE-2026-70437 Jenkins Webhook Plugin Timing Attack on Bearer Token
CVE-2026-70437 3.7 - Low - August 05, 2026

Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token.

Observable Timing Discrepancy

Jenkins External Workspace Manager Plugin 1.4.1: Insufficient Permission Check
CVE-2026-70436 4.3 - Medium - August 05, 2026

Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with Overall/Read permission to read files in workspaces they are not authorized to access.

AuthZ

Credential Leak in Jenkins SCM-Manager Plugin <=1.11.1 via Missing Permission Check
CVE-2026-70435 4.2 - Medium - August 05, 2026

A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

AuthZ

Jenkins SCM-Manager Plugin <1.11.1: CSRF credential leak
CVE-2026-70434 4.2 - Medium - August 05, 2026

A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Session Riding

Jenkins HCL AppScan Plugin 1.8.3 No Permission to Enumerate Credential IDs
CVE-2026-70433 4.3 - Medium - August 05, 2026

Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

AuthZ

CVE-2026-70432: CSRF in Jenkins Multijob Plugin v<669> Enables RCE
CVE-2026-70432 8.8 - High - August 05, 2026

A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM.

Session Riding

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Jenkins or by Jenkins? Click the Watch button to subscribe.

Jenkins
Vendor

Jenkins
Continuous Integration Engine

subscribe