Jenkins project Vulnerabilities and Affected Products
Vulnerabilities associated with Jenkins.
Products
Clear product- Jenkins124 vulnerabilities
- Jenkins Script Security Plugin29 vulnerabilities
- Jenkins Active Directory Plugin11 vulnerabilities
- Jenkins Pipeline: Groovy Plugin11 vulnerabilities
- Jenkins Email Extension Plugin9 vulnerabilities
- Jenkins Build Failure Analyzer Plugin8 vulnerabilities
- Jenkins NS-ND Integration Performance Publisher Plugin8 vulnerabilities
- Jenkins OpenId Connect Authentication Plugin8 vulnerabilities
- Jenkins Pipeline: Shared Groovy Libraries Plugin8 vulnerabilities
- Jenkins Amazon EC2 Plugin7 vulnerabilities
- Jenkins Configuration as Code Plugin7 vulnerabilities
- Jenkins Git Plugin7 vulnerabilities
- Jenkins Job Configuration History Plugin7 vulnerabilities
- Jenkins OpenShift Deployer Plugin7 vulnerabilities
- Jenkins Rundeck Plugin7 vulnerabilities
- Jenkins SAML Single Sign On(SSO) Plugin7 vulnerabilities
- Jenkins Artifactory Plugin6 vulnerabilities
- Jenkins Azure VM Agents Plugin6 vulnerabilities
- Jenkins Config File Provider Plugin6 vulnerabilities
- Jenkins Credentials Binding Plugin6 vulnerabilities
- Jenkins Deployment Dashboard Plugin6 vulnerabilities
- Jenkins ElectricFlow Plugin6 vulnerabilities
- Jenkins Git Parameter Plugin6 vulnerabilities
- Jenkins GitLab Authentication Plugin6 vulnerabilities
- Jenkins GitLab Plugin6 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Generated title:Jenkins Project Naming Strategy Unsafe InstantiationJenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators. CWE-284Aug 5, 2026 | CVSS2.7v3.1 | EPSS0.18% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-70429HIGH | Generated title:Jenkins Case-Insensitive User/Group Name Handling Impersonation VulnerabilityJenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted their permissions in some circumstances. CWE-178Aug 5, 2026 | CVSS8.1v3.1 | EPSS0.241% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-70428MEDIUM | Generated title:Jenkins Path Traversal in File Parameter NamesJenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the controller file system. CWE-22Aug 5, 2026 | CVSS4.3v3.1 | EPSS0.245% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-70427MEDIUM | Generated title:Jenkins Archive Extraction Symlink Arbitrary File WriteJenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins. CWE-59Aug 5, 2026 | CVSS4.3v3.1 | EPSS0.248% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-70426CRITICAL | Generated title:Jenkins Remoting JEP-200 Deserialization Filter BypassIn Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath. CWE-502Aug 5, 2026 | CVSS9.0v3.1 | EPSS0.292% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53442MEDIUM | Jenkins does not encrypt secrets from POST config.xml submissions before storing them in job configurationsJenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job configurations unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system. CWE-311Jun 10, 2026 | CVSS5.3v3.1 | EPSS0.19% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53441MEDIUM | Jenkins: Stored XSS vulnerability in node offline cause descriptionJenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the `POST config.xml` API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission. CWE-79Jun 10, 2026 | CVSS5.4v3.1 | EPSS0.261% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53440MEDIUM | Jenkins: Open Redirect phishing attacks possible via "from" parameter in "Delegate to servlet container"Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain. CWE-601Jun 10, 2026 | CVSS4.3v3.1 | EPSS0.239% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53439MEDIUM | Jenkins exposes other users' timezone and view names to users with Overall/Read permissionMissing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other users' configured timezone and to enumerate view names of other users' "My Views". CWE-862Jun 10, 2026 | CVSS4.3v3.1 | EPSS0.234% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53438MEDIUM | Jenkins: Missing permission check allows unauthorized cancellation of queue itemsA missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permission, but lacking Item/Read permission, to cancel queue items they do not have permission to view. CWE-862Jun 10, 2026 | CVSS4.3v3.1 | EPSS0.213% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53437HIGH | Jenkins Open Redirect Through Newline/Tab Characters in Redirect URLJenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between `//`, allowing attackers to perform phishing attacks. CWE-601Jun 10, 2026 | CVSS7.4v3.1 | EPSS0.364% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53436MEDIUM | Jenkins Open Redirect via Relative Path Segments in Post-Login Redirect URLJenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains relative path segments (`./` or `../`), allowing attackers to perform phishing attacks. CWE-601Jun 10, 2026 | CVSS4.3v3.1 | EPSS0.282% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53435HIGH | Jenkins arbitrary type deserialization from attacker-controlled config.xml allows remote code execution and user impersonationIn Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller. CWE-502Jun 10, 2026 | CVSS8.8v3.1 | EPSS19% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-33002HIGH | Jenkins has a DNS rebinding vulnerability in WebSocket CLI origin validationJenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expected origin for comparison using the Host or X-Forwarded-Host HTTP request headers, making it vulnerable to DNS rebinding attacks that allow bypassing origin validation. | CVSS7.5v3.1 | EPSS0.297% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-33001HIGH | Jenkins has a link following vulnerability allows arbitrary file creationJenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins. This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes. | CVSS8.8v3.1 | EPSS1.16% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-27100MEDIUM | Jenkins has a build information disclosure vulnerability through Run ParameterJenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values that refer to builds the user submitting the build does not have access to, allowing attackers with Item/Build and Item/Configure permission to obtain information about the existence of jobs, the existence of builds, and if a specified build exists, its display name. CWE-200Feb 18, 2026 | CVSS4.3v3.1 | EPSS0.333% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-27099HIGH | Jenkins has a stored XSS vulnerability in node offline cause descriptionJenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure or Agent/Disconnect permission. CWE-79Feb 18, 2026 | CVSS8.0v3.1 | EPSS0.464% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Jenkins has a CSRF vulnerability on the login formA cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers to trick users into logging in to the attacker's account. CWE-352Dec 10, 2025 | CVSS3.5v3.1 | EPSS0.184% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2025-67638MEDIUM | Jenkins's build authorization token is stored and displayed in plain textJenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them. CWE-312Dec 10, 2025 | CVSS4.3v3.1 | EPSS0.156% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-67637MEDIUM | Jenkins's build authorization token is stored and displayed in plain textJenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. CWE-312Dec 10, 2025 | CVSS4.3v3.1 | EPSS0.177% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-67636MEDIUM | Jenkins is missing a permission check on password fieldsA missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permission to view encrypted password values in views. CWE-862Dec 10, 2025 | CVSS4.3v3.1 | EPSS0.242% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-67635HIGH | Jenkins has a Denial of service vulnerability in HTTP-based CLIJenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service. CWE-404Dec 10, 2025 | CVSS7.5v3.1 | EPSS0.551% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59476MEDIUM | Jenkins has a log message injection vulnerabilityJenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output. | CVSS5.3v3.1 | EPSS0.335% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59475MEDIUM | Jenkins is missing a permission check in the authenticated users' profile menuJenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allowing attackers without Overall/Read permission to obtain limited information about the Jenkins configuration by listing available options in this menu (e.g., whether Credentials Plugin is installed). CWE-862Sep 17, 2025 | CVSS4.3v3.1 | EPSS0.448% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59474MEDIUM | Jenkins has a missing permission check, allowing users to obtain agent namesJenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission, allowing attackers without Overall/Read permission to list agent names through its sidepanel executors widget. | CVSS5.3v3.1 | EPSS4.74% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |