CVE-2026-70441: XSS
Published Aug 5, 2026
·Updated
Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Create or Item/Configure permission.
Affected Software
1 affected component
Jenkins Jenkins Summary Display Plugin<=1.15
Event History
Aug 5, 2026
CVE Published
via MITRE·05:40 PM
Data Sourced
via MITRE·05:40 PM
Description
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-70441?
The severity of CVE-2026-70441 is rated as risk 33.
2
Are there specific versions affected by CVE-2026-70441?
CVE-2026-70441 affects Jenkins Summary Display Plugin versions 1.15 and earlier.
3
How do I fix CVE-2026-70441?
To fix CVE-2026-70441, upgrade to the latest version of the Jenkins Summary Display Plugin that addresses this vulnerability.
4
What type of vulnerability is CVE-2026-70441?
CVE-2026-70441 is classified as a stored cross-site scripting (XSS) vulnerability.
5
Who is at risk from CVE-2026-70441?
Attackers with Item/Create or Item/Configure permissions in Jenkins are at risk of exploiting CVE-2026-70441.