PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-70441 Jenkins Project CVE debrief

The Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Create or Item/Configure permission. This vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. Affected product deployments exist in managed environments where Jenkins Summary Display Plugin is used. The vulnerability class is stored cross-site scripting (XSS). The likely operational impact is unauthorized code execution. Source-confidence limits are based on official CVE and NVD sources. Review context includes verifying affected product deployments, reviewing official advisories, and planning vendor-supported updates or mitigations.

Vendor
Jenkins Project
Product
Jenkins Summary Display Plugin
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-05
Original CVE updated
2026-08-05
Advisory published
2026-08-05
Advisory updated
2026-08-05

Who should care

Jenkins administrators and users with Item/Create or Item/Configure permissions should review and apply patches to prevent exploitation of this stored XSS vulnerability. Additionally, security teams and vulnerability management teams should be aware of the potential impact of this vulnerability on their Jenkins instances and take necessary precautions to prevent exploitation. Operators of Jenkins instances should also be aware of the potential risks and take steps to mitigate them. This includes restricting permissions, monitoring instances, and implementing additional security controls.

Technical summary

The Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, resulting in a stored cross-site scripting (XSS) vulnerability. This vulnerability is exploitable by attackers with Item/Create or Item/Configure permission. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. To prevent exploitation, it is recommended to review and apply patches for Jenkins Summary Display Plugin, restrict Item/Create and Item/Configure permissions to trusted users, and monitor Jenkins instances for suspicious activity.

Defensive priority

Medium-priority defensive review recommended due to stored cross-site scripting (XSS) vulnerability.

Recommended defensive actions

  • Review and apply vendor patches for Jenkins Summary Display Plugin
  • Restrict Item/Create and Item/Configure permissions to trusted users
  • Monitor Jenkins instance for suspicious activity
  • Consider implementing additional security controls for Jenkins instance
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

Evidence from official CVE and NVD sources indicates a stored XSS vulnerability in Jenkins Summary Display Plugin 1.15 and earlier. The plugin does not escape the job name in a JavaScript context in build report pages. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations. Additional security controls, such as restricting Item/Create and Item/Configure permissions to trusted users and monitoring Jenkins instances for suspicious activity, are recommended.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T18:17:13.930Z and has not been modified since then.