[NEW] [high] Jenkins Plugins: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Jenkins to execute arbitrary code, escalate privileges, bypass security measures, disclose confidential information, manipulate data as well as perform cross-site scripting (XSS) or server-side request forgery (SSRF) attacks.
CSIRTS triage
- What
- Multiple vulnerabilities in Jenkins plugins enable remote code execution, privilege escalation, authentication bypass, information disclosure, and SSRF attacks.
- Who is affected
- All Jenkins installations using affected plugins are at risk.
- Urgency
- High severity with multiple attack vectors including unauthenticated RCE; immediate patching is critical.
- Action
- Update all Jenkins plugins to patched versions; identify and list which specific plugins are affected and their version numbers from Jenkins security advisories.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Plugins
Get an email when a new Plugins advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2665
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-704260.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704270.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704280.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704290.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704300.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704310.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704320.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704330.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704340.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704350.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownJenkins Multiple Vulnerabilitieshkcert
- highCVE-2026-70448: Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML ext…nvd
- mediumCVE-2026-70447: Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers wit…nvd
- mediumCVE-2026-70446: Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with O…nvd
- mediumCVE-2026-70445: Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers w…nvd
- mediumCVE-2026-70444: A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier a…nvd
- mediumCVE-2026-70443: Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate con…nvd
- mediumCVE-2026-70442: Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the approp…nvd
- mediumCVE-2026-70441: Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript c…nvd
- mediumCVE-2026-70440: Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-co…nvd
- mediumCVE-2026-70439: Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allow…nvd
- mediumCVE-2026-70438: A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier al…nvd
Recent advisories for Jenkins Plugins
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-70448: Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML ext…nvd · 2026-08-05
- mediumCVE-2026-70447: Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers wit…nvd · 2026-08-05
- mediumCVE-2026-70446: Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with O…nvd · 2026-08-05
- mediumCVE-2026-70445: Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers w…nvd · 2026-08-05
- mediumCVE-2026-70444: A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier a…nvd · 2026-08-05
- mediumCVE-2026-70443: Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate con…nvd · 2026-08-05
More from CERT-Bund (BSI) Security Advisories
- medium[NEW] [medium] Apache CXF: Multiple Vulnerabilities2026-08-07
- medium[NEW] [medium] X.Org X11 Server (libXfont2): Multiple vulnerabilities allow execution of arbitrary code with a…2026-08-06
- high[UPDATE] [high] WSO2 API Manager: Multiple vulnerabilities2026-08-06
- medium[NEW] [medium] Red Hat OpenShift Container Platform (fast-uri, OpenTelemetry-Go): Multiple vulnerabilities2026-08-06
- medium[UPDATE] [medium] Red Hat OpenShift Container Platform (Router): Vulnerability allows bypassing security measu…2026-08-06