Jenkins
Jenkins Security Advisory 2026-04-29
2026-04-29 Apr 29, 2026 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2026-04-29/. 7 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2026-04-29/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
8 lines
Showing 1–8 of 8
CVE-2026-42519
BR2026-0000-008540
SECURITY-3662
unclaimed
Missing permission check in Script Security Plugin allows enumerating pending and approved classpaths
Credited as Ap4sh - Samy Medjahed
CVE-2026-42520
BR2026-0000-008541
SECURITY-3672
unclaimed
Path traversal vulnerability in Credentials Binding Plugin
Credited as Ap4sh - Samy Medjahed; and, independently, Dholland2022
CVE-2026-42520
BR2026-0000-008542
SECURITY-3672
unclaimed
Path traversal vulnerability in Credentials Binding Plugin
Credited as Muhamad Billy Sakti Baraja
CVE-2026-42521
BR2026-0000-008543
SECURITY-3676
unclaimed
Unsafe deserialization allows invoking parameterless constructors in Matrix Authorization Strategy Plugin
Credited as Arafat Ul Islam (elaichix), Cybersecurity Researcher, IUBAT, Bangladesh
CVE-2026-42522
BR2026-0000-008544
SECURITY-3702
unclaimed
Missing permission check in GitHub Branch Source Plugin allows performing a connection test
Credited as Samy Medjahed (Ap4sh)
CVE-2026-42522
BR2026-0000-008545
SECURITY-3702
unclaimed
Missing permission check in GitHub Branch Source Plugin allows performing a connection test
Credited as Eliott Laurie (Ethicxz)
CVE-2026-42523
BR2026-0000-008546
SECURITY-3704
unclaimed
XSS vulnerability in GitHub Plugin
Credited as dqh1
CVE-2026-42525
BR2026-0000-008547
SECURITY-3760
unclaimed
Open redirect vulnerability in Microsoft Entra ID (previously Azure AD) Plugin
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)