PatchSiren

Jenkins Project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Jenkins Project CVE published 2026-09-16

CVE-2026-92141

CVE-2026-92141 debrief based on the supplied source corpus. The Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks. This vulnerability affects Jenkins administrators and security teams, who should assess exposure and phishing risk in their deployments. The vulnerability requires verification of affected ve [truncated]

MEDIUM Jenkins Project CVE published 2026-09-16

CVE-2026-92140

CVE-2026-92140 is a stored cross-site scripting (XSS) vulnerability in Jenkins Gitee Plugin versions 1301.v8957053c7902 and earlier. The vulnerability allows attackers to inject malicious scripts into build causes via the Gitee push webhook payloads, potentially leading to security issues. Defenders should assess exposure and risk of malicious script injection. Security teams should verify version informa [truncated]

MEDIUM Jenkins Project CVE published 2026-09-16

CVE-2026-92139

CVE-2026-92139 debrief based on the supplied source corpus. The Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier has a vulnerability that allows attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload. This issue affects Jenkins administrators and users who have configured Bitbucket credentials in Jenkins. They should verify their configuration and [truncated]

MEDIUM Jenkins Project CVE published 2026-09-16

CVE-2026-92138

CVE-2026-92138 debrief: The Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier is vulnerable to OAuth flow hijacking, allowing attackers to obtain an access token on behalf of the victim. This vulnerability has a medium severity and requires immediate attention from defenders responsible for Jenkins deployments. The plugin's OAuth authorization endpoint reads the `oauth_callback` URL from the s [truncated]

HIGH Jenkins Project CVE published 2026-09-16

CVE-2026-92137

CVE-2026-92137 debrief: The Jenkins Robot Framework Plugin 6.2.2 and earlier vulnerability allows for arbitrary file creation, potentially leading to remote code execution. Attackers with Item/Configure permission can create or replace arbitrary files on the Jenkins controller file system. Defenders should assess exposure, verify archive directory configurations, and apply patches or updates to mitigate t [truncated]

HIGH Jenkins Project CVE published 2026-09-16

CVE-2026-92136

The Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability. This vulnerability is exploitable by attackers with Item/Configure permission. The CVE record was published on 2026-09-16T14:17:15.587Z and has not been modified since then. The vulnerability allows attackers [truncated]

HIGH Jenkins Project CVE published 2026-09-16

CVE-2026-92135

CVE-2026-92135 is a stored cross-site scripting (XSS) vulnerability in Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier. The plugin does not validate the coverage results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a javascript: scheme URL as identifier. This vulnerability can lead to unauthorized actions or data theft. De [truncated]

HIGH Jenkins Project CVE published 2026-09-16

CVE-2026-92134

CVE-2026-92134 is a stored cross-site scripting (XSS) vulnerability in Jenkins Warnings Plugin versions 13.10258.va_17d49a_78c3b_ and earlier. The vulnerability allows attackers with Item/Configure permission to inject malicious JavaScript code via the analysis results ID when submitting a job configuration through the REST API. This issue arises from inadequate validation of the analysis results ID, enab [truncated]

MEDIUM Jenkins Project CVE published 2026-09-16

CVE-2026-92133

CVE-2026-92133 debrief: The Jenkins GitLab Plugin vulnerability allows unauthorized access to GitLab API token credentials due to improper caching. This affects Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier. Defenders should verify and restrict access to plugin configurations, especially in multi-user environments. The vulnerability enables attackers with Item/Configure permission to access GitL [truncated]

MEDIUM Jenkins Project CVE published 2026-09-16

CVE-2026-92132

CVE-2026-92132 is a vulnerability in the Jenkins Gradle Plugin that allows attackers to capture the Develocity access key by having Jenkins connect to an attacker-specified URL, potentially leading to unauthorized access to the Develocity server. Defenders responsible for Jenkins deployments should assess exposure and verify the plugin version to prevent potential capture of Develocity access keys. The vu [truncated]

MEDIUM Jenkins Project CVE published 2026-09-16

CVE-2026-92131

CVE-2026-92131 is a path traversal vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier. The plugin does not restrict library paths to relative paths inside the SCM checkout and follows symbolic links to locations outside the SCM checkout. This allows attackers able to configure Pipelines to read files in a resources directory and delete files in a test directory on th [truncated]

LOW Jenkins Project CVE published 2026-09-16

CVE-2026-92130

CVE-2026-92130 is a vulnerability in Jenkins Pipeline: Multibranch Plugin versions 841.vec5b_9e1806ec and earlier. The plugin does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to. This issue has a CVSS score of 3.1 and a severity of LOW.

HIGH Jenkins Project CVE published 2026-09-16

CVE-2026-92129

CVE-2026-92129 is a high-severity vulnerability in the Jenkins Script Security Plugin. The plugin does not check calls from sandboxed scripts to methods added dynamically to a class at runtime, allowing attackers with permission to define and run sandboxed scripts to bypass the sandbox protection and execute code outside the sandbox. This vulnerability affects Jenkins administrators and users who define a [truncated]

HIGH Jenkins Project CVE published 2026-09-16

CVE-2026-92128

CVE-2026-92128 is a high-severity vulnerability in the Jenkins Script Security Plugin. The plugin downloads a JAR file specified by URL twice, confirming the approval of the first download and loading the classpath entries from the second. This allows attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins controller JVM.

HIGH Jenkins Project CVE published 2026-09-16

CVE-2026-92127

CVE-2026-92127 debrief based on the supplied source corpus. The CVE record was published on 2026-09-16T14:17:14.720Z and has not been modified since then. The vulnerability in Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM. This occurs when a user with Overall/Administer permission copies an item or u [truncated]

HIGH Jenkins Project CVE published 2026-09-16

CVE-2026-92126

The Jenkins Script Security Plugin has a vulnerability allowing attackers with permission to define and run sandboxed scripts to execute code outside the sandbox. This issue affects versions up to 1415.v9a_f9b_3a_c253d. Defenders should assess exposure, prioritize remediation, and verify sandbox restrictions. The vulnerability is caused by the plugin's failure to reject @Builder annotations whose builderS [truncated]

HIGH Jenkins Project CVE published 2026-09-16

CVE-2026-92125

CVE-2026-92125 debrief based on the supplied source corpus. The vulnerability is in the Jenkins Script Security Plugin, specifically in versions up to 1415.v9a_f9b_3a_c253d. This plugin does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to run an arbitrary AST transformation at compile time. This bypass [truncated]

HIGH Jenkins Project CVE published 2026-09-16

CVE-2026-92124

CVE-2026-92124 is a high-severity vulnerability in the Jenkins Script Security Plugin. The plugin incorrectly checks the operations Groovy will perform with the elements it reads from a collection that a sandboxed script casts to another type, allowing attackers to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM. This issue affects Jenkins Script Secur [truncated]

HIGH Jenkins Project CVE published 2026-09-16

CVE-2026-92123

CVE-2026-92123 is a high-severity vulnerability in Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier. The plugin fails to intercept operations on a null receiver, allowing attackers with permission to define and run sandboxed scripts to bypass protection and execute arbitrary code in the Jenkins controller JVM. This could lead to disruption of Jenkins services and potential code execution. [truncated]

HIGH Jenkins Project CVE published 2026-09-16

CVE-2026-92122

CVE-2026-92122 debrief based on the supplied source corpus. The vulnerability is in Jenkins Script Security Plugin versions 1415.v9a_f9b_3a_c253d and earlier. It allows attackers with permission to define and run sandboxed scripts to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM. Defenders should assess exposure and apply remediation, focusing on upd [truncated]

MEDIUM Jenkins Project CVE published 2026-09-02

CVE-2026-84677

The CVE-2026-84677 vulnerability affects Jenkins update-center2 versions 3.18.3 and earlier. It is a stored cross-site scripting (XSS) vulnerability that allows attackers to provide a plugin for hosting, leading to potential exploitation. The vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM. Jenkins administrators, security teams, and developers hosting plugins for Jenkins update-cent [truncated]

HIGH Jenkins Project CVE published 2026-09-02

CVE-2026-84675

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T16:17:32.130Z and has not been modified since then. This OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build. Affected organizations should pr [truncated]

MEDIUM Jenkins Project CVE published 2026-09-02

CVE-2026-84674

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T16:17:32.033Z and has not been modified since then. CVE-2026-84674 is a medium-severity vulnerability in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and earlier. The plugin fails to perform adequate permission checks, allowing attackers with Overall/Read permission to enumerate credentials IDs of c [truncated]

HIGH Jenkins Project CVE published 2026-09-02

CVE-2026-84673

The Jenkins Customizable Header Plugin version 295.v2544b_ca_19b_97 and earlier is vulnerable to stored cross-site scripting (XSS). Attackers can configure a custom SVG icon containing inline JavaScript, potentially leading to unauthorized actions or data breaches. This CVE record was published on 2026-09-02T16:17:31.940Z. Affected administrators should prioritize patching and review plugin configurations [truncated]

HIGH Jenkins Project CVE published 2026-09-02

CVE-2026-84671

The Jenkins File Parameter Plugin, specifically version 425.v3fa_801681b_5e and earlier, is vulnerable to remote code execution due to improper handling of Stapler data binding. This allows attackers to write files to arbitrary locations on the Jenkins controller file system. The CVE record was published on 2026-09-02T16:17:31.737Z and has not been modified since then. Administrators of Jenkins instances [truncated]

HIGH Jenkins Project CVE published 2026-09-02

CVE-2026-84670

The Jenkins Performance Plugin, version 1015.v09ca_52b_3370e and earlier, contains a vulnerability that allows attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller. This is due to the plugin's failure to restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller.

HIGH Jenkins Project CVE published 2026-09-02

CVE-2026-84669

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T16:17:31.537Z and has not been modified since then. This CVE-2026-84669 vulnerability affects Jenkins Allure Plugin versions 2.35.2 and earlier, allowing attackers with Item/Read permission to read arbitrary files on the Jenkins controller's file system due to a path traversal vulnerability. The [truncated]

HIGH Jenkins Project CVE published 2026-09-02

CVE-2026-84668

The Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier is vulnerable to SAML identity provider metadata file overwriting through Stapler data binding. This allows attackers to replace the metadata file with attacker-controlled content and authenticate as any user. Administrators of Jenkins instances with the SAML Plugin should verify their plugin version and restrict access to the Stapler data binding [truncated]

MEDIUM Jenkins Project CVE published 2026-09-02

CVE-2026-84666

The CVE record for CVE-2026-84666 was published on 2026-09-02T16:17:31.247Z. This vulnerability affects Jenkins Job Configuration History Plugin version 1367.vc8fa_b_15101dc and earlier. The vulnerability allows attackers to redirect history storage to an attacker-specified directory and modify history recording settings through Stapler data binding. This issue has a medium severity and requires attention [truncated]

HIGH Jenkins Project CVE published 2026-09-02

CVE-2026-84665

The Jenkins SonarQube Scanner Plugin versions 2.18.3 and earlier are vulnerable to stored cross-site scripting (XSS). The plugin does not limit URL schemes for dashboard links created from SonarQube scanner results, allowing the `javascript:` scheme. This vulnerability is exploitable by attackers with Item/Configure permission, potentially leading to malicious script injection. Administrators should be aw [truncated]