https://seclists.org/oss-sec/2026/q2/1015: Multiple vulnerabilities in Jenkins plugins

Published Jun 24, 2026
·
Updated

Affected Software

18 affected components
Jenkins Script Security Plugin<=1402.v94c9ce464861
Jenkins Git client Plugin<=6.6.0
Jenkins Pipeline: Groovy Plugin<=4331.v9d06ed4658ff
Jenkins GitHub Branch Source Plugin<=1967.1969.v205fd594c821
Jenkins Git Parameter Plugin<=462.vdcf3df2ed2ca_
Jenkins Job Configuration History Plugin<=1356.ve360da_6c523a_
Jenkins Active Directory Plugin<=2.41.1
Jenkins MCP Server Plugin<=0.177.v629fdb_2557fe
Jenkins Bitbucket Push and Pull Request Plugin<=3.3.8
Jenkins Priority Sorter Plugin<=936.v2c01c6b_84449
Jenkins Gitee Plugin<=1288.v18b_deb_c9069b_
Jenkins EC2 Fleet Plugin<=4.2.3.539.v8fedff2a_81c3
Jenkins External Workspace Manager Plugin<=1.3.2
Jenkins Contrast Continuous Application Security Plugin<=3.11
Jenkins OWASP ZAP Plugin<=1.0.7
Jenkins FitNesse Plugin<=1.36
Jenkins Assembla Plugin<=1.4
Jenkins Zowe zDevOps Plugin<=1.1.3.50.ve350c9b_450b_1
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What are the key vulnerabilities addressed in Jenkins plugins identified in the advisory?

The advisory details multiple vulnerabilities across several Jenkins plugins including potential remote code execution, improper access control, and cross-site scripting issues.

2

What is the severity of the vulnerabilities in Jenkins plugins?

The vulnerabilities are rated with varying severity levels, with some potentially allowing critical remote code execution.

3

How do I fix the vulnerabilities in Jenkins plugins mentioned in the advisory?

To fix the vulnerabilities, update the affected Jenkins plugins to their latest versions as specified in the advisory.

4

Are there any workarounds for the vulnerabilities in Jenkins plugins?

Temporary workarounds may include restricting access to Jenkins or disabling the affected plugins until they can be updated.

5

What Jenkins plugins are affected by the vulnerabilities listed in the advisory?

Affected Jenkins plugins include the Active Directory Plugin, Git client Plugin, Script Security Plugin, and others as noted in the advisory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203