[NEW] [high] Jenkins Plugins: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Jenkins to execute arbitrary code, escalate privileges, bypass security measures, disclose confidential information, manipulate data as well as perform cross-site scripting (XSS) or server-side request forgery (SSRF) attacks.
CSIRTS triage
- What
- Multiple vulnerabilities in Jenkins plugins enable remote code execution, privilege escalation, authentication bypass, information disclosure, and SSRF attacks.
- Who is affected
- All Jenkins installations using affected plugins are at risk.
- Urgency
- High severity with multiple attack vectors including unauthenticated RCE; immediate patching is critical.
- Action
- Update all Jenkins plugins to patched versions; identify and list which specific plugins are affected and their version numbers from Jenkins security advisories.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Plugins
Get an email when a new Plugins advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2665
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-704260.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704270.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704280.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704290.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704300.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704310.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704320.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704330.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704340.09% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704350.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownJenkins Multiple Vulnerabilitieshkcert
- highCVE-2026-70448: Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML ext…nvd
- mediumCVE-2026-70447: Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers wit…nvd
- mediumCVE-2026-70446: Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with O…nvd
- mediumCVE-2026-70445: Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers w…nvd
- mediumCVE-2026-70444: A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier a…nvd
- mediumCVE-2026-70443: Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate con…nvd
- mediumCVE-2026-70442: Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the approp…nvd
- mediumCVE-2026-70441: Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript c…nvd
- mediumCVE-2026-70440: Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-co…nvd
- mediumCVE-2026-70439: Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allow…nvd
- mediumCVE-2026-70438: A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier al…nvd
More from CERT-Bund (BSI) Security Advisories
- high[UPDATE] [hoch] Red Hat Enterprise Linux (postgis, virtuoso-opensource): Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Red Hat Enterprise Linux: Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Service2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-11
- high[UPDATE] [hoch] OpenSSL: Mehrere Schwachstellen2026-09-11