Jenkins
Jenkins Security Advisory 2026-08-05
2026-08-05 Aug 5, 2026 Source: Vendor
Imported by the Jenkins advisory catcher from https://www.jenkins.io/security/advisory/2026-08-05/. 20 SECURITY issues listed. Draft. Review before publishing.
Source of record
The credited names below are quoted verbatim from the vendor's own advisory:
https://www.jenkins.io/security/advisory/2026-08-05/
Are you credited here?
Sign in and claim your line: it is yours immediately, no review queue.
The name the vendor printed stays next to your handle for anyone to check against the advisory above,
and any member who thinks a claim is wrong can refute it.
Credited
27 lines
Showing 1–27 of 27
CVE-2026-70426
BR2026-0000-007272
SECURITY-3911
unclaimed
Agent-to-controller deserialization filter bypass
Credited as Abdullah Hamza (notre3l)
CVE-2026-70448
BR2026-0000-007273
SECURITY-3899
unclaimed
XXE vulnerability in Ivy Report Plugin
Credited as Alexander Rozanov, Innopolis University
Acknowledgement
BR2026-0000-007274
SECURITY-3823
unclaimed
SECURITY-3823
Credited as Daniel Beck, CloudBees, Inc.
Acknowledgement
BR2026-0000-007275
SECURITY-3823
unclaimed
SECURITY-3823
Credited as Sanghyeon Lee (h9e0n, https://github.com/isanghyeon)
Acknowledgement
BR2026-0000-007276
SECURITY-3823
unclaimed
SECURITY-3823
Credited as Kevin Guerroudj, CloudBees, Inc.
CVE-2026-70437
BR2026-0000-007277
SECURITY-3918
unclaimed
Non-constant time webhook bearer token comparison in Webhook Secret Credentials Provider Plugin
Credited as Mykhailo Kholiev
CVE-2026-70429
BR2026-0000-007278
SECURITY-3924
unclaimed
Improper handling of case sensitivity allows privilege escalation
Credited as Samy Medjahed (Ap4sh)
CVE-2026-70429
BR2026-0000-007279
SECURITY-3924
unclaimed
Improper handling of case sensitivity allows privilege escalation
Credited as Eliott Laurie (Ethicxz)
CVE-2026-70428
BR2026-0000-007280
SECURITY-3927
unclaimed
Path traversal vulnerability in file parameters
Credited as Samy Medjahed (Ap4sh)
CVE-2026-70428
BR2026-0000-007281
SECURITY-3927
unclaimed
Path traversal vulnerability in file parameters
Credited as Eliott Laurie (Ethicxz)
CVE-2026-70427
BR2026-0000-007282
SECURITY-3930
unclaimed
Link following vulnerability allows arbitrary file creation
Credited as Samy Medjahed (Ap4sh)
CVE-2026-70427
BR2026-0000-007283
SECURITY-3930
unclaimed
Link following vulnerability allows arbitrary file creation
Credited as Eliott Laurie (Ethicxz)
CVE-2026-70436
BR2026-0000-007284
SECURITY-3907
unclaimed
Missing permission check in External Workspace Manager Plugin allows reading workspace files
Credited as Ugur Ozer, AI Risk Management
CVE-2026-70430
BR2026-0000-007285
SECURITY-3916
unclaimed
Users with Overall/Manage permission can instantiate any types related to configuration
Credited as Vitaly Simonovich (https://www.vitalysim.com)
CVE-2026-70440
BR2026-0000-007286
SECURITY-3749
unclaimed
Stored XSS vulnerability in Qualys Container Scanning Connector Plugin
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)
CVE-2026-70441
BR2026-0000-007287
SECURITY-3750
unclaimed
Stored XSS vulnerability in Summary Display Plugin
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)
CVE-2026-70442
BR2026-0000-007288
SECURITY-3752
unclaimed
Exposure of System-scoped credentials in Google Chat Notification Plugin
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)
CVE-2026-70443
BR2026-0000-007289
SECURITY-3756
unclaimed
Exposure of System-scoped credentials in Horreum Plugin
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)
CVE-2026-70444
BR2026-0000-007290
SECURITY-3763
unclaimed
Missing permission check in Violation Comments to GitLab Plugin allows enumerating credentials IDs
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)
CVE-2026-70438
BR2026-0000-007291
SECURITY-3768
unclaimed
Missing permission checks in Parameterized Remote Trigger Plugin allow enumerating credentials IDs
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)
CVE-2026-70433
BR2026-0000-007292
SECURITY-3771
unclaimed
Missing permission checks in HCL AppScan Plugin allow enumerating credentials IDs
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)
CVE-2026-70446
BR2026-0000-007293
SECURITY-3772
unclaimed
Missing permission checks in CodeSonar Plugin allow enumerating credentials IDs
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)
CVE-2026-70447
BR2026-0000-007294
SECURITY-3773
unclaimed
Missing permission checks in AWS CodeBuild Plugin allow enumerating credentials IDs
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)
CVE-2026-70439
BR2026-0000-007295
SECURITY-3779
unclaimed
Missing permission checks in XML Job to Job DSL Plugin
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)
CVE-2026-70445
BR2026-0000-007296
SECURITY-3770
unclaimed
Missing permission checks in Sauce OnDemand Plugin allow enumerating credentials IDs
Credited as dyingman1 (https://github.com/dyingman1, redpoc Offensive Security Team)
CVE-2026-70445
BR2026-0000-007297
SECURITY-3770
unclaimed
Missing permission checks in Sauce OnDemand Plugin allow enumerating credentials IDs
Credited as Kai Aizen, SnailSploit
CVE-2026-70434
BR2026-0000-007298
SECURITY-3888
unclaimed
CSRF vulnerability and missing permission checks in SCM-Manager Plugin
Credited as khoadb175