Jenkins
Jenkins Security Advisory 2026-05-27
2026-05-27 May 27, 2026 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2026-05-27/. 11 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2026-05-27/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
12 lines
Showing 1–12 of 12
CVE-2026-48916
BR2026-0000-008528
SECURITY-3654
unclaimed
RCE vulnerability from unvalidated LDAP referrals in LDAP Plugin
Credited as Icare (https://x.com/Icare1337)
CVE-2026-48916
BR2026-0000-008529
SECURITY-3654
unclaimed
RCE vulnerability from unvalidated LDAP referrals in LDAP Plugin
Credited as truff (https://x.com/truffzor); and, independently, Arad Inbar, Erez Cohen, Nir Somech, Ben Grinberg, Daniel Lubel, Adiel Sol from DREAM
CVE-2026-48922
BR2026-0000-008530
SECURITY-3790
unclaimed
Path traversal vulnerability in Credentials Binding Plugin
Credited as Mitchell Benjamin, Revamp Studio, and, independently, Qianheng Wang
CVE-2026-48921
BR2026-0000-008531
SECURITY-3727
unclaimed
Arbitrary file read vulnerability through symbolic links in Pipeline: Groovy Libraries Plugin
Credited as Olawale Titiloye(https://www.linkedin.com/in/olawale-t-02673a18a/); and, independently, Samy Medjahed (Ap4sh)
CVE-2026-48921
BR2026-0000-008532
SECURITY-3727
unclaimed
Arbitrary file read vulnerability through symbolic links in Pipeline: Groovy Libraries Plugin
Credited as Eliott Laurie (Ethicxz)
CVE-2026-48921
BR2026-0000-008533
SECURITY-3727
unclaimed
Arbitrary file read vulnerability through symbolic links in Pipeline: Groovy Libraries Plugin
Credited as @surrealgrain on GitHub
CVE-2026-48923
BR2026-0000-008534
SECURITY-3671
unclaimed
Missing permission check in AppSpider Plugin allows sending requests
Credited as Tommaso Gregori (p1s1o)
CVE-2026-48927
BR2026-0000-008535
SECURITY-3486
unclaimed
Stored XSS vulnerability in buildgraph-view Plugin
Credited as Yaroslav Afenkin
CVE-2026-48924
BR2026-0000-008536
SECURITY-3761
unclaimed
Open redirect vulnerability in Bitbucket OAuth Plugin
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)
CVE-2026-48925
BR2026-0000-008537
SECURITY-3776
unclaimed
CSRF vulnerability in GitHub Integration Plugin
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)
CVE-2026-9674
BR2026-0000-008538
SECURITY-3781
unclaimed
CSRF vulnerability in Multijob Plugin allows resuming builds
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)
CVE-2026-48926
BR2026-0000-008539
SECURITY-3783
unclaimed
Missing permission check in Job Import Plugin allows enumerating credentials IDs
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)