CVE-2026-70448
An attacker can exploit multiple vulnerabilities in Jenkins to execute arbitrary code, escalate privileges, bypass security measures, disclose confidential information, manipulate data as well as perform cross-site scripting (XSS) or server-side request forgery (SSRF) attacks.
CSIRTS triage
- What
- Multiple unspecified vulnerabilities affect Jenkins Core and 15 associated plugins.
- Who is affected
- Deployments of Jenkins Core and users of AWS CodeBuild, CodeSonar, External Workspace Manager, Google Chat Notification, HCL AppScan, Horreum, Ivy Report, Multijob, Parameterized Remote Trigger, Qualys Container Scanning Connector, Sauce OnDemand, SCM-Manager, Summary Display, Violation Comments to GitLab, and Webhook Secret Credentials Provider plugins.
- Urgency
- Severity unknown; eight CVEs assigned indicate multiple impact vectors requiring immediate investigation.
- Action
- Consult Jenkins Security Advisory 2026-08-05 for specific vulnerability details and apply recommended patches for Core and affected plugins.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-70448
Get an email if CVE-2026-70448 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
Advisory coverage (3)
- high[NEW] [high] Jenkins Plugins: Multiple vulnerabilitiescert-bund · 2026-08-06
- highCVE-2026-70448: Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML ext…nvd · 2026-08-05
- unknownJenkins Security Advisory 2026-08-05jenkins · 2026-08-05
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-70448)