| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Known vulnerabilities affecting Jenkins products and systems
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-9674 | A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows attackers to resume failed Multijob builds. | 4.3 | 163 | Neutral | No |
| Yes |
| CVE-2026-48927 | Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or views. | 5.5 | 226 | Neutral | No | Yes |
| CVE-2026-48925 | A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attackers to attackers to trigger a build for a pull request. | 4.3 | 163 | Neutral | No | Yes |
| CVE-2026-48924 | Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks. | 4.3 | 142 | Neutral | No | Yes |
| CVE-2026-48923 | Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to connect to an attacker-spec... | 4.3 | 99 | Neutral | No | Yes |
| CVE-2026-48922 | Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to wr... | 7.5 | 465 | Neutral | No | Yes |
| CVE-2026-48921 | Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a ... | 7.5 | 379 | Neutral | No | Yes |
| CVE-2026-48920 | Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that ca... | 8.8 | 667 | Neutral | No | Yes |
| CVE-2026-48919 | Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation. | 6.6 | 342 | Neutral | No | Yes |
| CVE-2026-48918 | Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default. | 6.6 | 342 | Neutral | No | Yes |
| CVE-2026-42525 | Jenkins Microsoft Entra ID (previously Azure AD) Plugin versions 666.v6060de32f87d and earlier do not restrict the redirect URL after login. This allows attackers to perform phishing attacks by havin... | 4.3 | 142 | Neutral | No | Yes |
| CVE-2026-42524 | Jenkins HTML Publisher Plugin versoins 427 and earlier do not escape the job name and URL in the legacy wrapper file. This results in a stored cross-site scripting (XSS) vulnerability exploitable by ... | 8.0 | 563 | Neutral | No | Yes |
| CVE-2026-42523 | In Jenkins GitHub Plugin versions 1.46.0 and earlier, the JavaScript that validates the "GitHub hook trigger for GITScm polling" feature improperly processes the current job URL. This results in a st... | 9.0 | 659 | Neutral | No | Yes |
| CVE-2026-42522 | Jenkins GitHub Branch Source Plugin versions 1967.vdea_d580c1a_b_a_ and earlier do not perform a permission check in a method implementing form validation. This allows attackers with Overall/Read per... | 4.3 | 163 | Neutral | No | Yes |
| CVE-2026-42521 | Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specified in configuration when deserializing inheritance strategie... | 6.5 | 338 | Neutral | No | Yes |
| CVE-2026-42520 | Jenkins Credentials Binding Plugin versions 719.v80e905ef14eb_ and earlier do not sanitize file names for file and zip file credentials. This allows attackers able to provide credentials to a job to ... | 7.5 | 501 | Neutral | No | Yes |
| CVE-2026-42519 | Jenkins Script Security Plugin versions 1399.ve6a_66547f6e1 and earlier do not perform a permission check in an HTTP endpoint. This allows attackers with Overall/Read permission to enumerate pending ... | 4.3 | 163 | Neutral | No | Yes |
| CVE-2026-33004 | Jenkins LoadNinja Plugin 2.1 and earlier does not mask LoadNinja API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them. | 4.3 | 99 | Neutral | No | Yes |
| CVE-2026-33003 | Jenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or... | 4.3 | 99 | Neutral | No | Yes |
| CVE-2026-33002 | Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expected ... | 7.5 | 379 | Neutral | No | Yes |