Known Vulnerabilities for products from Jenkins

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Jenkins".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-84677 json Not Provided 2026-09-02 2026-09-02
CVE-2026-84676 json Not Provided 2026-09-02 2026-09-02
CVE-2026-84675 json Not Provided 2026-09-02 2026-09-02
CVE-2026-84674 json Not Provided 2026-09-02 2026-09-02
CVE-2026-84673 json Not Provided 2026-09-02 2026-09-02
CVE-2026-84672 json Not Provided 2026-09-02 2026-09-02
CVE-2026-84671 json Not Provided 2026-09-02 2026-09-02
CVE-2026-84670 json Not Provided 2026-09-02 2026-09-02
CVE-2026-84669 json Not Provided 2026-09-02 2026-09-02
CVE-2026-84668 json Not Provided 2026-09-02 2026-09-02
CVE-2026-70430 json Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of... Not Provided 2026-08-05 2026-09-08
CVE-2026-70429 json Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, a... Not Provided 2026-08-05 2026-09-08
CVE-2026-70428 json Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file paramet... Not Provided 2026-08-05 2026-09-08
CVE-2026-70427 json Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during ... Not Provided 2026-08-05 2026-09-08
CVE-2026-57307 json A missing permission check in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers with Overall/... Not Provided 2026-06-24 2026-06-26
CVE-2026-57306 json A cross-site request forgery (CSRF) vulnerability in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows ... Not Provided 2026-06-24 2026-06-26
CVE-2026-57305 json A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Plugin 1.4 and earlier allows attackers to connect to a... Not Provided 2026-06-24 2026-06-25
CVE-2026-57304 json A missing permission check in Jenkins Assembla Plugin 1.4 and earlier allows attackers with Overall/Read permission to connec... Not Provided 2026-06-24 2026-06-25
CVE-2026-57303 json Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allow... Not Provided 2026-06-24 2026-06-25
CVE-2026-57302 json Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, wher... Not Provided 2026-06-24 2026-06-26

Known software with vulnerabilities from Jenkins

Type Vendor Product Version
ApplicationJenkins360 Fireline1.0
ApplicationJenkinsAbsint Astree1.0.0
ApplicationJenkinsActive Choices0.1
ApplicationJenkinsActive Directory1.0
ApplicationJenkinsAlauda Devops Pipeline2.3.2
ApplicationJenkinsAlauda Kubernetes Support2.0.0
ApplicationJenkinsAmazon Ec21.0
ApplicationJenkinsAmazon Sns Build Notifier-
ApplicationJenkinsAmazon Web Services Serverless Application Model1.2.2
ApplicationJenkinsAmazon Web Services Service Application Model1.2.2
ApplicationJenkinsAnchore Container Image Scanner1.0.0
ApplicationJenkinsAndroid Lint1.0
ApplicationJenkinsAnsible0.1
ApplicationJenkinsAnsible Tower0.5.0
ApplicationJenkinsAppdynamics1.0.0
ApplicationJenkinsApplatix-
ApplicationJenkinsAppspider1.0.12
ApplicationJenkinsAqua Microscanner1.0.0
ApplicationJenkinsAqua Security Scanner-
ApplicationJenkinsAqua Security Severless Scanner1.0.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report