PatchSiren cyber security CVE debrief
CVE-2026-70439 Jenkins Project CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T18:17:13.713Z and has not been modified since then. CVE-2026-70439 is a medium-severity vulnerability in Jenkins XML Job to Job DSL Plugin versions 0.1.13 and earlier. The plugin fails to perform necessary permission checks, enabling attackers without appropriate permissions to invoke the conversion functionality. This issue has been publicly disclosed and CVE and NVD entries have been created/updated. Administrators and users of Jenkins instances with the XML Job to Job DSL Plugin installed should be aware of this vulnerability. Due to the medium severity and potential for unauthorized use of conversion functionality, attention from Jenkins administrators and security teams is warranted.
- Vendor
- Jenkins Project
- Product
- Jenkins XML Job to Job DSL Plugin
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-05
- Original CVE updated
- 2026-08-05
- Advisory published
- 2026-08-05
- Advisory updated
- 2026-08-05
Who should care
Administrators and users of Jenkins instances with the XML Job to Job DSL Plugin installed should be aware of this vulnerability. Due to the medium severity and potential for unauthorized use of conversion functionality, attention from Jenkins administrators and security teams is warranted.
Technical summary
CVE-2026-70439 is a medium-severity vulnerability in Jenkins XML Job to Job DSL Plugin versions 0.1.13 and earlier. The plugin fails to perform necessary permission checks, enabling attackers without appropriate permissions to invoke the conversion functionality. This issue has been publicly disclosed and CVE and NVD entries have been created/updated.
Defensive priority
Medium-severity vulnerability in Jenkins XML Job to Job DSL Plugin, requiring permission checks for conversion functionality.
Recommended defensive actions
- Review and update Jenkins XML Job to Job DSL Plugin to version beyond 0.1.13 if available.
- Implement strict permission checks for conversion functionality in Jenkins.
- Monitor Jenkins instance for unauthorized use of conversion functionality.
Evidence notes
Evidence from official CVE and NVD sources indicates a medium-severity vulnerability in Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier. The plugin does not perform permission checks, allowing attackers to invoke conversion functionality without appropriate permissions.
Official resources
-
CVE-2026-70439 CVE record
CVE.org
-
CVE-2026-70439 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T18:17:13.713Z and has not been modified since then.