These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-84663 is a cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 798.v5cc688825312 and earlier. This vulnerability allows attackers to delete shared library caches. The CVE record was published on 2026-09-02T16:17:30.950Z. Administrators and users of the affected plugin should apply the vendor-provided patch or update to a non-vulnerable version to prevent p [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T16:17:30.857Z and has not been modified since then. This medium-severity vulnerability in Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler data binding, potentially enabling attackers to connect to attacker-specified URLs. This could lead [truncated]
CVE-2026-84658 debrief based on the supplied source corpus. The vulnerability exists in Jenkins Script Security Plugin versions up to 1412.v7737b_3405f86. The `@DataBoundConstructor` annotation on a constructor that loads script approval configuration allows attackers able to submit certain forms to read that configuration. Defenders should assess exposure and verify remediation, particularly for Jenkins [truncated]
CVE-2026-84657 is a vulnerability in Jenkins that allows attackers with Item/Build permission to cancel builds started by other users. The build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion. This vulnerability can disrupt CI/CD pipelines and build processes. Defenders should assess exposure and prioritize remediation to pre [truncated]
A missing permission check in Jenkins allows attackers with Item/Read permission to read build parameter names and values of jobs they have no access to. This vulnerability exists in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier. Defenders should prioritize verifying exposure in Jenkins environments, especially where Item/Read permission is granted to users or roles, and assess the impact of potentia [truncated]
CVE-2026-84653 is a low-severity vulnerability affecting Jenkins versions 2.421 through 2.579 and LTS versions 2.426.1 through 2.568.2. The vulnerability allows attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to. Defenders should assess exposure and prioritize remediation based on their specific Jenkins deployment.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T16:17:29.620Z and has not been modified since then. The Stapler plugin in Jenkins, versions 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (excluding 2088.2093.vd7c3e58008a_6), embeds the user's CSRF token as a string literal in an HTTP endpoint serving dynamically generated JavaScript resourc [truncated]
CVE-2026-84646 is a vulnerability in Jenkins that allows attackers with Overall/Read permission to create user objects by submitting crafted XML. The CVE record was published on 2026-09-02T16:17:29.313Z and has been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Jenkins versions 2.579 and earlier, as well as LTS versions 2.568.2 and earlier. The vulnerability allows u [truncated]
CVE-2026-84645 debrief based on the supplied source corpus. The vulnerability in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, allows objects of types marked as storing their configuration in independent top-level configuration files in Jenkins to appear as nested field values in user-submitted `config.xml` documents and subsequently handle HTTP requests via Stapler, resulting in remote code executi [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T18:17:14.570Z and has not been modified since then. CVE-2026-70447 is a vulnerability in Jenkins AWS CodeBuild Plugin 0.59 and earlier. The plugin does not perform adequate permission checks, allowing attackers with Overall/Read permission to enumerate credentials IDs stored in Jenkins. This vuln [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T18:17:14.237Z and has not been modified since then. The Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier has a missing permission check, allowing attackers with Overall/Read permission to enumerate credential IDs stored in Jenkins. This vulnerability affects Jenkins administrators a [truncated]
The CVE-2026-70443 record details a vulnerability in Jenkins Horreum Plugin versions 0.16.162.v33b_4a_a_b_5f828 and earlier. This vulnerability allows attackers with Item/Configure permission to have Jenkins send credentials they are not entitled to use to the administrator-configured Horreum URL, due to improper context setting for credentials lookup. The issue can lead to potential credential misuse. Ad [truncated]
The Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Create or Item/Configure permission. This vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. Affected product deployments exist in managed environments where Jenkins Sum [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T18:17:13.813Z and has not been modified since then. The Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a JavaScript context, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Co [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T18:17:13.713Z and has not been modified since then. CVE-2026-70439 is a medium-severity vulnerability in Jenkins XML Job to Job DSL Plugin versions 0.1.13 and earlier. The plugin fails to perform necessary permission checks, enabling attackers without appropriate permissions to invoke the convers [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T18:17:13.350Z and has not been modified since then. This vulnerability affects Jenkins External Workspace Manager Plugin versions 1.4.1 and earlier. The issue allows attackers with Overall/Read permission to read files in unauthorized workspaces due to a permission check issue. The plugin does no [truncated]
A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM. This vulnerability has a high severity and can be exploited by attackers to execute arbitrary code. Affected product deployments should be confirmed in managed environments and assigned an owner for follow-up. [truncated]
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, handles case-insensitivity in user names and group names inconsistently. This inconsistency allows attackers to create new users or groups with names that case-insensitively match other characters, potentially leading to impersonation or unauthorized permission grants. The vulnerability can be exploited by attackers able to create new users or groups, wh [truncated]
CVE-2026-57297 is a MEDIUM severity vulnerability in Jenkins Contrast Continuous Application Security Plugin. The CVE record was published on 2026-06-24T14:17:35.877Z and has not been modified since then. This vulnerability allows attackers with Overall/Read permission to connect to an attacker-specified URL, potentially leading to unauthorized interactions with external systems. The CVSS score of 4.3 ind [truncated]
CVE-2026-53442 is a medium-severity vulnerability affecting Jenkins versions 2.567 and earlier, as well as LTS versions 2.555.2 and earlier. The vulnerability causes Jenkins to store secrets from POST config.xml submissions in an unencrypted format in job config.xml files on the Jenkins controller. This allows users with Item/Extended Read permission or access to the Jenkins controller file system to view [truncated]
CVE-2026-53441 is a stored cross-site scripting (XSS) vulnerability in Jenkins 2.483 through 2.567 and LTS 2.492.1 through 2.555.2. The vulnerability occurs because Jenkins does not escape the user-provided description of a generic offline cause that could be set through the `POST config.xml` API. This allows attackers with Agent/Configure permission to exploit the vulnerability.
CVE-2026-53440 is a medium-severity vulnerability in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier. The vulnerability occurs because the 'from' parameter in the 'Delegate to servlet container' security realm is not properly validated, allowing attackers to redirect users to an attacker-controlled domain after login, which can be used for phishing attacks.
CVE-2026-53439 is a medium-severity vulnerability in Jenkins. The issue allows attackers with Overall/Read permission to determine other users' configured timezone and enumerate view names of other users' 'My Views'. This vulnerability affects Jenkins 2.567 and earlier, as well as LTS 2.555.2 and earlier.
CVE-2026-53438 is a medium-severity vulnerability in Jenkins that allows attackers with Item/Cancel permission, but lacking Item/Read permission, to cancel queue items they do not have permission to view. This issue affects Jenkins 2.567 and earlier, as well as LTS 2.555.2 and earlier.
CVE-2026-53437 is a medium-severity vulnerability in Jenkins that allows attackers to perform phishing attacks. The vulnerability is caused by improper validation of redirect URLs after login, which can be exploited by attackers to redirect users to malicious sites. The vulnerability affects Jenkins versions 2.567 and earlier, as well as LTS versions 2.555.2 and earlier.
CVE-2026-53436 is a medium-severity vulnerability in Jenkins that allows attackers to perform phishing attacks due to improper validation of redirect URLs after login. The vulnerability affects Jenkins 2.567 and earlier, as well as LTS 2.555.2 and earlier. The issue arises from the application's failure to properly determine if a redirect URL contains relative path segments (`./` or `../`), which can be e [truncated]
CVE-2026-53435 is a high-severity vulnerability in Jenkins, a popular automation server. The vulnerability has a CVSS score of 8.8 and was published on [cvePublishedAt]. It affects Jenkins versions 2.567 and earlier, as well as LTS versions 2.555.2 and earlier. The vulnerability allows attackers to deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` subm [truncated]
A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows attackers to resume failed Multijob builds. The vulnerability was published on 2026-05-27 and carries a CVSS 3.1 score of 4.3 (MEDIUM severity). The attack vector is network-based with low attack complexity, requiring no privileges but user interaction. The vulnerability affects confidential [truncated]
A stored cross-site scripting (XSS) vulnerability exists in Jenkins buildgraph-view Plugin versions 1.8 and earlier. The plugin fails to escape the build URL, allowing attackers with job or view configuration privileges to inject malicious scripts. When other users view affected build graphs, the injected scripts execute in their browser context. This represents a medium-severity privilege escalation vect [truncated]
A missing permission check in Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs stored in Jenkins. This information disclosure vulnerability (CWE-269) has a CVSS 3.1 score of 4.3 (Medium severity). The issue was disclosed in the Jenkins security advisory dated 2026-05-27. No known exploitation in the wild or ransomware camp [truncated]