[NEW] [high] Jenkins: Multiple Vulnerabilities
A remote, anonymous attacker can exploit multiple vulnerabilities in Jenkins and various plugins to disclose or manipulate data, conduct cross-site scripting (XSS), execute arbitrary code, or take over another user's session.
CSIRTS triage
- What
- Multiple vulnerabilities in Jenkins and plugins allow remote anonymous attackers to disclose or manipulate data, conduct XSS, execute arbitrary code, and hijack user sessions.
- Who is affected
- Jenkins instances, particularly those exposed to untrusted networks, are affected; anonymous exploitation is possible.
- Urgency
- High severity; unauthenticated code execution on CI/CD infrastructure poses critical risk to software supply chain.
- Action
- Update Jenkins and all plugins to patched versions addressing CVE-2026-84645 through CVE-2026-84652.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Jenkins
Get an email when a new Jenkins advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3166
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownJenkins Multiple Vulnerabilitieshkcert
- mediumCVE-2026-84677: Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names…nvd
- mediumCVE-2026-84676: Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job…nvd
- highCVE-2026-84675: OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attacker…nvd
- mediumCVE-2026-84674: Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and earlier allow attac…nvd
- highCVE-2026-84673: Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plu…nvd
- highCVE-2026-84672: Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants …nvd
- highCVE-2026-84671: Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrar…nvd
- highCVE-2026-84670: Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that…nvd
- highCVE-2026-84669: A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers wi…nvd
- highCVE-2026-84668: Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity pro…nvd
- highCVE-2026-84667: Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configurati…nvd
Recent advisories for Jenkins
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownJenkins Multiple Vulnerabilitieshkcert · 2026-09-03
- mediumCVE-2026-84677: Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names…nvd · 2026-09-02
- mediumCVE-2026-84676: Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job…nvd · 2026-09-02
- highCVE-2026-84675: OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attacker…nvd · 2026-09-02
- mediumCVE-2026-84674: Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and earlier allow attac…nvd · 2026-09-02
- highCVE-2026-84673: Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plu…nvd · 2026-09-02
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] IBM i: Multiple Vulnerabilities2026-09-03
- medium[NEW] [medium] Sonatype Nexus Repository Manager: Multiple Vulnerabilities Enable Denial of Service2026-09-03
- high[NEW] [high] BigBlueButton: Multiple Vulnerabilities2026-09-03
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-09-03
- medium[NEW] [medium] Red Hat Enterprise Linux (libsolv, aardvark-dns): Multiple vulnerabilities2026-09-03