Jenkins
Jenkins Security Advisory 2026-03-18
2026-03-18 Mar 18, 2026 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2026-03-18/. 3 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2026-03-18/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
3 lines
Showing 1–3 of 3
CVE-2026-33003
BR2026-0000-008548
SECURITY-3642
unclaimed
API keys stored and displayed in plain text by LoadNinja Plugin
Credited as Adam Jordan
CVE-2026-33001
BR2026-0000-008549
SECURITY-3657
unclaimed
Link following vulnerability allows arbitrary file creation
Credited as Nguyen Ngoc Quang Bach aka maysbachs (https://www.linkedin.com/in/quang-bach-ngoc-nguyen-59b2b7304/); and, independently, Elie Metahri (Airbus Protect Offensive Security Team); Vitaly Simonovich, Senior Security Research
CVE-2026-33002
BR2026-0000-008550
SECURITY-3674
unclaimed
DNS rebinding vulnerability in WebSocket CLI origin validation
Credited as TallowX92, and, independently, Babauca