

Jenkins weekly and LTS core, plus Multijob, HCL AppScan, SCM-Manager, and several other plugins with active use.
Vulnerabilities enable arbitrary code execution, unauthorized access, privilege escalation, information disclosure, and cross-site request forgery attacks.
Disclosed 5th August 2026; several plugins remain unpatched, with Jenkins core and LTS fixes available now.
Agent-to-controller communication, file parameter handling, HTTP endpoints, and Groovy scripting features exposed to authenticated users.
Deserialization filter gaps, unsafe symbolic link handling, path traversal flaws, and missing permission checks across plugins.
Attackers with agent access or specific permissions bypass filters, write arbitrary files, or execute unsandboxed Groovy code.
Successful exploitation can lead to controller compromise, credential theft, arbitrary file writes, and unauthorized administrative access.
Jenkins underpins software delivery pipelines; controller compromise risks build secrets, source code, and deployment credentials.
Update Jenkins core to version 2.576 or LTS 2.568.2; update affected plugins to their fixed releases.
Review controller logs for unusual agent activity, unexpected file writes, and unauthorized Groovy script execution attempts.
Jenkins Security Advisory
Trusted by clients worldwide






Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.




