Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Jenkins

Jenkins Security Advisory 2026-06-24

2026-06-24 Jun 24, 2026 Source: Vendor

Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2026-06-24/. 16 SECURITY issues listed. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.jenkins.io/security/advisory/2026-06-24/
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

15 lines
Showing 1–15 of 15
CVE-2026-57288 BR2026-0000-007299 SECURITY-3651 unclaimed
LDAP injection vulnerability in Active Directory Plugin
Credited as Arad Inbar, Ben Grinberg, Nir Somech from DREAM, and, independently, Nahit Sogutlu (http://github.com/Dogru-Isim)
CVE-2026-57300 BR2026-0000-007300 SECURITY-3759 unclaimed
Missing permission check in MCP Server Plugin allows reading Pipeline replay scripts
Credited as Heechan, and, independently, YeJun Won
Acknowledgement BR2026-0000-007301 SECURITY-3692 unclaimed
SECURITY-3692
Credited as Kai Aizen (SnailSploit)
CVE-2026-57287 BR2026-0000-007302 SECURITY-3742 unclaimed
Encrypted values of secrets in job and agent configurations not redacted by Job Configuration History Plugin
Credited as Ophion Security in collaboration with Claude and Anthropic Research
CVE-2026-57301 BR2026-0000-007303 SECURITY-3649 unclaimed
Builds executed on the Jenkins controller by OWASP ZAP Plugin can lead to RCE
Credited as Pablo Picurelli Ortiz (superpegaso2703) of Universidad Rey Juan Carlos
CVE-2026-57282 BR2026-0000-007304 SECURITY-3723 unclaimed
OS command injection vulnerability on agents in Git client Plugin
Credited as Ravindu Wickramasinghe
CVE-2026-57302 BR2026-0000-007305 SECURITY-3555 unclaimed
Passwords stored in plain text by FitNesse Plugin
Credited as Romuald Moisan, Aix Marseille University
CVE-2026-57285 BR2026-0000-007306 SECURITY-3808 unclaimed
Missing permission check allows enumerating GitHub Enterprise server URLs in GitHub Branch Source Plugin
Credited as Suman Roy (https://linkedin.com/in/sumanrox)
CVE-2026-57286 BR2026-0000-007307 SECURITY-3745 unclaimed
Missing permission check in Git Parameter Plugin allows listing SCM branch and tag names
Credited as SungpilHan (@EQSTLab)
CVE-2026-57306 BR2026-0000-007308 SECURITY-3747 unclaimed
CSRF vulnerability and missing permission check in Zowe zDevOps Plugin
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)
Acknowledgement BR2026-0000-007309 SECURITY-3762 unclaimed
SECURITY-3762
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)
CVE-2026-57290 BR2026-0000-007310 SECURITY-3769 unclaimed
CSRF vulnerability in Priority Sorter Plugin
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)
CVE-2026-57294 BR2026-0000-007311 SECURITY-3774 unclaimed
CSRF vulnerability and missing permission checks in EC2 Fleet Plugin
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)
CVE-2026-57296 BR2026-0000-007312 SECURITY-3777 unclaimed
Path traversal vulnerability in External Workspace Manager Plugin
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)
CVE-2026-57289 BR2026-0000-007313 SECURITY-3856 unclaimed
SSL/TLS certificate validation unconditionally disabled by Bitbucket Push and Pull Request Plugin
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)