Known Vulnerabilities for products from Jenkins

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Jenkins".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-92141 json Not Provided 2026-09-16 2026-09-16
CVE-2026-92140 json Not Provided 2026-09-16 2026-09-16
CVE-2026-92139 json Not Provided 2026-09-16 2026-09-16
CVE-2026-92138 json Not Provided 2026-09-16 2026-09-16
CVE-2026-92137 json Not Provided 2026-09-16 2026-09-16
CVE-2026-92136 json Not Provided 2026-09-16 2026-09-16
CVE-2026-92135 json Not Provided 2026-09-16 2026-09-16
CVE-2026-92134 json Not Provided 2026-09-16 2026-09-16
CVE-2026-92133 json Not Provided 2026-09-16 2026-09-16
CVE-2026-92132 json Not Provided 2026-09-16 2026-09-16
CVE-2026-92129 json Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added... Not Provided 2026-09-16 2026-09-21
CVE-2026-92128 json Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the ... Not Provided 2026-09-16 2026-09-21
CVE-2026-92127 json Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item conf... Not Provided 2026-09-16 2026-09-21
CVE-2026-92126 json Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy m... Not Provided 2026-09-16 2026-09-27
CVE-2026-92125 json Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation... Not Provided 2026-09-16 2026-09-21
CVE-2026-92124 json Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements ... Not Provided 2026-09-16 2026-09-21
CVE-2026-92123 json Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (... Not Provided 2026-09-16 2026-09-21
CVE-2026-92122 json Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created w... Not Provided 2026-09-16 2026-09-21
CVE-2026-84659 json Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that control... Not Provided 2026-09-02 2026-09-22
CVE-2026-84658 json Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor t... Not Provided 2026-09-02 2026-09-22

Known software with vulnerabilities from Jenkins

Type Vendor Product Version
ApplicationJenkins360 Fireline1.0
ApplicationJenkinsAbsint Astree1.0.0
ApplicationJenkinsActive Choices0.1
ApplicationJenkinsActive Directory1.0
ApplicationJenkinsAlauda Devops Pipeline2.3.2
ApplicationJenkinsAlauda Kubernetes Support2.0.0
ApplicationJenkinsAmazon Ec21.0
ApplicationJenkinsAmazon Sns Build Notifier-
ApplicationJenkinsAmazon Web Services Serverless Application Model1.2.2
ApplicationJenkinsAmazon Web Services Service Application Model1.2.2
ApplicationJenkinsAnchore Container Image Scanner1.0.0
ApplicationJenkinsAndroid Lint1.0
ApplicationJenkinsAnsible0.1
ApplicationJenkinsAnsible Tower0.5.0
ApplicationJenkinsAppdynamics1.0.0
ApplicationJenkinsApplatix-
ApplicationJenkinsAppspider1.0.12
ApplicationJenkinsAqua Microscanner1.0.0
ApplicationJenkinsAqua Security Scanner-
ApplicationJenkinsAqua Security Severless Scanner1.0.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report