CVE-2026-70439: Medium severity Jenkins XML Job to Job DSL Plugin vulnerability
Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appropriate permissions to invoke the conversion functionality.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jenkins XML Job to Job DSL Pluginto a version that resolves this vulnerability.Fixed in 0.1.13 - Compensating control
Ensure only authenticated users with appropriate Jenkins permissions can access/invoke the XML Job to Job DSL Plugin conversion functionality (e.g., restrict access to the job conversion endpoints/actions to authorized roles).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70439?
CVE-2026-70439 has a risk score of 45, indicating a moderate severity level.
How do I fix CVE-2026-70439?
To fix CVE-2026-70439, upgrade the Jenkins XML Job to Job DSL Plugin to version 0.1.14 or later.
What is CVE-2026-70439 about?
CVE-2026-70439 describes a vulnerability in Jenkins XML Job to Job DSL Plugin versions 0.1.13 and earlier that lacks proper permission checks.
Who is affected by CVE-2026-70439?
Users of Jenkins XML Job to Job DSL Plugin versions 0.1.13 and earlier are affected by CVE-2026-70439.
Can CVE-2026-70439 be exploited remotely?
Yes, CVE-2026-70439 can be exploited remotely by attackers who do not have the necessary permissions.