Jenkins Script Security Plugin 1415.v9af9b3ac253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute code outside the sandbox.
Jenkins Script Security Plugin 1415.v9af9b3ac253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and loading the classpath entries from the second, allowing attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins controller JVM.
Jenkins Script Security Plugin 1415.v9af9b3ac253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item, or updates that configuration through the REST API or CLI, allowing attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins controller JVM.
Jenkins Script Security Plugin 1415.v9af9b3ac253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to run an arbitrary AST transformation at compile time, bypassing the sandbox protection and executing arbitrary code in the context of the Jenkins controller JVM.
Jenkins Script Security Plugin 1415.v9af9b3ac253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to execute code outside the sandbox if a suitable class is present on the classpath of the component that evaluates the script.
Jenkins Script Security Plugin 1415.v9af9b3ac253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a sandboxed script casts to another type but performs the cast on the collection itself, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
Jenkins Script Security Plugin 1415.v9af9b3ac253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribute accesses, and array accesses), allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
Jenkins Script Security Plugin 1415.v9af9b3ac253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a value to an interface, if the value inherits a method of the same name as an interface method, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
Jenkins is an open source automation server which enables developers around the world to reliably build, test, and deploy their software.
The following releases contain fixes for security vulnerabilities:
Bitbucket Push and Pull Request Plugin 4.1.0 Bitbucket Server Integration Plugin 6.0.2 Coverage Plugin 3.3361.v0626103a67e6 Gitee Plugin 1304.v2702f1d71cde GitLab Plugin 1.2152.veec0897048b0 Gradle Plugin 2.20.1253.vc116f0763aeb Keycloak Authentication Plugin 2.4.2 OWASP Dependency-Check Plugin 5.6.5 Pipeline: Groovy Libraries Plugin 806.v408277b33d1d Pipeline: Multibranch Plugin 842.v3ab59b57be6e Robot Framework Plugin 6.3.0 Script Security Plugin 1422.v06869826dd9b Warnings Plugin 13.10259.v80f407cb03ae
Summaries of the vulnerabilities are below. More details, severity, and attribution can be found here: https://www.jenkins.io/security/advisory/2026-09-16/
We provide advance notification for security updates on this mailing list: https://groups.google.com/d/forum/jenkinsci-advisories
If you discover security vulnerabilities in Jenkins, please report them as described here: https://www.jenkins.io/security/#reporting-vulnerabilities
---
SECURITY-3929 / CVE-2026-92122 Script Security Plugin provides a sandbox feature that allows running user-provided scripts safely by intercepting and checking potentially unsafe operations.
Groovy coerces a value to an interface by creating a proxy that forwards each interface method call to a method of the same name on that value.
Script Security Plugin 1415.v9af9b3ac253d and earlier does not check the method that the proxy calls when the value inherits a method of the same name as an interface method.
This allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
SECURITY-3931 / CVE-2026-92123 Script Security Plugin provides a sandbox feature that allows running user-provided scripts safely by intercepting and checking potentially unsafe operations.
Script Security Plugin 1415.v9af9b3ac253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribute accesses, and array accesses).
This allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
SECURITY-3923 / CVE-2026-92124 Script Security Plugin provides a sandbox feature that allows running user-provided scripts safely by intercepting and checking potentially unsafe operations.
Groovy casts a collection to another type using the elements of that collection, either passing them to a constructor of that type or casting each of them.
Script Security Plugin 1415.v9af9b3ac253d and earlier checks the operations Groovy will perform with the elements it reads from the collection, but performs the cast on the collection itself rather than on the elements it checked.
This allows attackers with permission to define and run sandboxed scripts, including Pipelines, to have the cast performed on different elements by overriding the methods of a collection, bypassing the sandbox protection and executing arbitrary code in the context of the Jenkins controller JVM.
SECURITY-3925 (1) / CVE-2026-92125 Script Security Plugin provides a sandbox feature that allows running user-provided scripts safely by intercepting and checking potentially unsafe operations.
Script Security Plugin 1415.v9af9b3ac253d and earlier does not reject the @GroovyASTTransformationClass annotation, which a script can use to link an annotation type it declares to an arbitrary AST transformation, causing Groovy to run that transformation at compile time, before the sandbox is applied.
This allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
SECURITY-3925 (2) / CVE-2026-92126 Script Security Plugin provides a sandbox feature that allows running user-provided scripts safely by intercepting and checking potentially unsafe operations.
Groovy's @Builder annotation generates builder code at compile time using the strategy class named by its builderStrategy member, which can be one of the strategies provided by Groovy or a custom implementation.
Script Security Plugin 1415.v9af9b3ac253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, which causes Groovy to instantiate that class at compile time, before the sandbox is applied.
This may allow attackers with permission to define and run sandboxed scripts, including Pipelines, to execute code outside the sandbox, in the rare case that a suitable class is present on the classpath of the component that evaluates the script.
SECURITY-3897 / CVE-2026-92127 Script Security Plugin allows Groovy scripts to load classpath entries from JAR files, which administrators must approve before any script is allowed to use them.
Script Security Plugin 1415.v9af9b3ac253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item, or updates that configuration through the REST API or CLI, allowing attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins controller JVM.
SECURITY-3932 / CVE-2026-92128 Script Security Plugin allows Groovy scripts to load classpath entries from JAR files, specified either by file path or by URL, which administrators must approve before any script is allowed to use them.
Script Security Plugin 1415.v9af9b3ac253d and earlier downloads a JAR file specified by URL twice when a script is evaluated, confirming the approval of the first download and loading the classpath entries from the second.
This results in a time-of-check to time-of-use (TOCTOU) race condition that allows attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins controller JVM.
NOTE: Exploitation requires an already approved JAR file to be served from an attacker-controlled server.
SECURITY-3977 / CVE-2026-92129 Script Security Plugin provides a sandbox feature that allows running user-provided scripts safely by intercepting and checking potentially unsafe operations.
Groovy allows an existing class to be extended at runtime with additional methods.
Script Security Plugin 1415.v9af9b3ac253d and earlier does not check calls to such methods from sandboxed scripts.
This allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute code outside the sandbox.
NOTE: Exploitation requires that the dynamically added methods have already been defined by code running outside the sandbox, e.g. by a plugin, as sandboxed scripts cannot extend a class themselves.
SECURITY-3729 / CVE-2026-92130 Pipeline: Multibranch Plugin 841.vec5b9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing the use of System-scoped credentials otherwise reserved for the global configuration.
This allows attackers with Item/Configure permission to access and capture credentials they are not entitled to use.
SECURITY-3796 / CVE-2026-92131 Pipeline: Groovy Libraries Plugin provides the library step to retrieve a shared library from an SCM, using a library path to specify the directory containing the library inside the SCM checkout.
Pipeline: Groovy Libraries Plugin 805.vafc79344957d and earlier does not restrict that library path to a relative path inside the SCM checkout.
Additionally, it follows symbolic links to locations outside of the SCM checkout when retrieving the library.
This results in a path traversal vulnerability, allowing attackers able to configure Pipelines to read files in a resources directory and to delete files in a test directory on the Jenkins controller file system.
SECURITY-4028 / CVE-2026-92132 Gradle Plugin provides global options for administrators to detect build scan links in build logs, and to show an enriched build scan summary for those build scans on the build page.
In Gradle Plugin 2.19.1252.v15196b5a6e10 and earlier, the enriched build scan summary requests data from the build scan link detected in the build log, even when a Develocity server URL is configured in the global configuration.
This allows attackers able to control the build log to capture the Develocity access key configured in the global configuration by having Jenkins connect to an attacker-specified URL.
SECURITY-3851 / CVE-2026-92133 GitLab Plugin allows jobs to override the globally configured GitLab API token credentials with an alternative one, and caches the GitLab API client it builds for those credentials.
GitLab Plugin 1.2149.vcfc32c82bf7f and earlier derives the cache key from the credentials ID alone, omitting the folder in which the credentials are resolved, resulting in the GitLab API token credentials being taken from the folder of the job that created the cache entry.
This allows attackers with Item/Configure permission to access GitLab API token credentials they are not entitled to use.
SECURITY-3937 / CVE-2026-92134 Warnings Plugin uses analysis results IDs to create the links to analysis results on the Jenkins UI.
Warnings Plugin 13.10258.va17d49a78c3b and earlier does not validate the analysis results ID when a job configuration is submitted through the REST API. This allows attackers with Item/Configure permission to use a javascript: scheme URL as identifier, resulting in a stored cross-site scripting (XSS) vulnerability.
TIP: On Jenkins 2.539 and newer, LTS 2.541.1 and newer, enforcing Content Security Policy protection mitigates this vulnerability.
SECURITY-4118 / CVE-2026-92135 Coverage Plugin uses coverage results IDs to create the links to coverage results on the Jenkins UI.
Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configuration is submitted through the REST API. This allows attackers with Item/Configure permission to use a javascript: scheme URL as identifier, resulting in a stored cross-site scripting (XSS) vulnerability.
TIP: On Jenkins 2.539 and newer, LTS 2.541.1 and newer, enforcing Content Security Policy protection mitigates this vulnerability.
SECURITY-3992 / CVE-2026-92136 OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
TIP: On Jenkins 2.539 and newer, LTS 2.541.1 and newer, enforcing Content Security Policy protection mitigates this vulnerability.
SECURITY-3971 / CVE-2026-92137 Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the build directory on the Jenkins controller.
This allows attackers with Item/Configure permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content, which can lead to remote code execution.
SECURITY-3778 / CVE-2026-92138 Bitbucket Server Integration Plugin implements an OAuth provider for Bitbucket Server.
The OAuth authorization endpoint in Bitbucket Server Integration Plugin 6.0.1 and earlier reads the oauthcallback URL from the submitted form rather than from the server-side stored request token. An attacker who can manipulate the form submission can cause Jenkins to redirect the authorizing user's browser to an arbitrary URL. The redirect includes the oauthtoken and oauthverifier parameters, allowing the attacker to complete the OAuth flow and obtain an access token on behalf of the victim.
NOTE: Exploiting this vulnerability requires the attacker to have previously registered an OAuth consumer (requires Overall/Administer permission) and to be able to intercept and modify the victim's form submission.
SECURITY-3980 / CVE-2026-92139 Bitbucket Push and Pull Request Plugin provides a webhook endpoint at /bitbucket-hook/ to receive webhook notifications.
When acting on these notifications, Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs.
This allows attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload.
SECURITY-4027 / CVE-2026-92140 Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to trigger builds via the Gitee Plugin webhook endpoint.
SECURITY-3767 / CVE-2026-92141 Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login.
This allows attackers to perform phishing attacks by having users go to a Jenkins URL that will forward them to a different site after successful authentication.
-- CONFIDENTIALITY NOTICE: This email and any attachments contain confidential and proprietary information of CloudBees intended only for the named recipient(s). Unauthorized use or distribution is prohibited. If you received this in error, please notify the sender and delete this email.
Jenkins Script Security Plugin 1412.v7737b3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, allowing attackers to disable it through Stapler data binding.
Jenkins Script Security Plugin 1412.v7737b3405f86 and earlier uses the @DataBoundConstructor annotation on a constructor that loads script approval configuration, allowing attackers able to submit certain forms to read that configuration.
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scripts to execute code outside the sandbox if a suitable script is present on the classpath of the component that evaluates the script.
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scripts to execute code outside the sandbox if a suitable script is present on the classpath of the component that evaluates the script.
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attackers able to provide such scripts to invoke arbitrary constructors and bypass the sandbox protection.
Jenkins is an open source automation server which enables developers around the world to reliably build, test, and deploy their software.
The following releases contain fixes for security vulnerabilities:
Active Directory Plugin 2.41.2 Bitbucket Push and Pull Request Plugin 3.3.9 Contrast Continuous Application Security Plugin 3.12 EC2 Fleet Plugin 4.2.3.540.va6eedb7bc112 External Workspace Manager Plugin 1.4.0 Git client Plugin 6.6.1 Git Parameter Plugin 462.463.v496a59f698e5 Gitee Plugin 1292.v2559f2f3f2c0 GitHub Branch Source Plugin 1967.1970.vd86979736546 Job Configuration History Plugin 1367.vc8fab15101dc MCP Server Plugin 0.178.vffe5ae770f3b Pipeline: Groovy Plugin 4331.4333.v50ab076c5199 Priority Sorter Plugin 936.937.v5581d0b2ccba Script Security Plugin 1402.1405.vc96e74964250
Additionally, we announce unresolved security issues in the following plugins:
Assembla Plugin FitNesse Plugin OWASP ZAP Plugin Zowe zDevOps Plugin
Summaries of the vulnerabilities are below. More details, severity, and attribution can be found here: https://www.jenkins.io/security/advisory/2026-06-24/
We provide advance notification for security updates on this mailing list: https://groups.google.com/d/forum/jenkinsci-advisories
If you discover security vulnerabilities in Jenkins, please report them as described here: https://www.jenkins.io/security/#reporting-vulnerabilities
---
SECURITY-3792 / CVE-2026-57280 Script Security Plugin provides a sandbox feature that allows running user-provided scripts safely by intercepting and checking potentially unsafe operations.
Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type cast applied to each element of the iterated collection in a typed for loop (e.g. for (Type t in collection)), as this cast is performed during bytecode generation rather than in the transformed script AST.
This allows attackers able to provide sandboxed scripts to invoke constructors of arbitrary types without those invocations being checked by the sandbox, bypassing the sandbox protection. This can be used to execute arbitrary code on the Jenkins controller.
SECURITY-3793 / CVE-2026-57281 Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations such as @CompileStatic and @TypeChecked that carry an extensions member, which causes Groovy to load and execute a script from the classpath at compile time, before the sandbox is applied.
This may allow attackers able to define and run sandboxed scripts to execute code outside the sandbox, in the rare case that a suitable Groovy script is present on the classpath of the component that evaluates the script.
NOTE: The Jenkins security team has been unable to identify any Groovy source files in Jenkins core or plugins that would allow attackers to execute dangerous code. While the severity of this issue is declared as High due to the potential impact, successful exploitation is considered very unlikely.
SECURITY-3723 / CVE-2026-57282 Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into the SSH wrapper script generated by the "Manually provided keys" Git Host Key Verification strategy on Unix agents.
This allows attackers able to control the name of a build's working directory (e.g. through a build parameter that determines the workspace directory) to inject shell command substitution and execute arbitrary commands on the agent.
NOTE: This vulnerability only has an impact when attackers can control working directories (e.g., the argument to the dir(…) Pipeline step) while not being able to control the Pipeline itself or the programs or build scripts it executes.
NOTE: This vulnerability has been reported through the Jenkins Bug Bounty Program sponsored by the European Commission.
SECURITY-3677 / CVE-2026-57283 (CSRF) & CVE-2026-57284 (unrestricted instantiation of types) Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, instantiating any type with a constructor annotated with @DataBoundConstructor in response to a request.
This allows attackers to have Pipeline: Groovy Plugin instantiate types related to job or system configuration other than Pipeline steps.
Additionally, this HTTP endpoint can be accessed using the GET method and does not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability. This allows attackers to create a script approval request attributed to another user, impersonating a trusted user when social engineering an administrator into approving a malicious script.
NOTE: This vulnerability has been reported through the Jenkins Bug Bounty Program sponsored by the European Commission.
SECURITY-3808 / CVE-2026-57285 GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier does not perform a permission check in an HTTP endpoint that lists the GitHub API endpoints configured in the global plugin configuration.
This allows attackers with Overall/Read permission to obtain the URLs of GitHub Enterprise servers configured by administrators.
NOTE: This vulnerability has been reported through the Jenkins Bug Bounty Program sponsored by the European Commission.
SECURITY-3745 / CVE-2026-57286 Git Parameter Plugin 462.vdcf3df2ed2ca and earlier does not perform a permission check in an HTTP endpoint that populates the list of values for Git parameters by querying the SCM configured on a job, using the SCM credentials configured in Jenkins.
This allows attackers with Item/Read permission to obtain information about the SCM repository used by a job they would otherwise be unable to access, such as branch names, tag names, and revision metadata.
SECURITY-3742 / CVE-2026-57287 Job Configuration History Plugin 1356.ve360da6c523a and earlier does not redact the encrypted values of secrets when displaying historical job and agent configurations through its "View as XML" / "(RAW)" feature and its configuration diff views.
This allows attackers with Item/Extended Read permission (but not Item/Configure permission) to view the encrypted values of secrets, such as build trigger tokens, that Jenkins would otherwise redact from the configuration shown to them.
SECURITY-3651 / CVE-2026-57288 In Active Directory Plugin 2.41.1 and earlier, the Windows native (ADSI) authentication path does not escape the user name before building the LDAP search filter.
This allows unauthenticated attackers to inject LDAP wildcard characters into the user name, enabling them to enumerate directory user and group names, and to authenticate as a matching user when they know that user's password but not their exact user name.
SECURITY-3759 / CVE-2026-57300 MCP Server Plugin 0.177.v629fdb2557fe and earlier does not perform a permission check in the getReplayScripts MCP tool that returns the replay script of a Pipeline build.
This allows attackers with Item/Read permission to obtain the Pipeline script of jobs.
SECURITY-3856 / CVE-2026-57289 Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for the connections it makes to Bitbucket Server using Bearer token authentication.
Because the Bearer token is transmitted in these requests, this allows attackers able to intercept network traffic to capture the token and impersonate the Jenkins controller to Bitbucket Server.
SECURITY-3769 / CVE-2026-57290 Priority Sorter Plugin 936.v2c01c6b84449 and earlier does not require POST requests in an HTTP endpoint that saves the global job priority configuration.
This allows attackers to overwrite the global job priority configuration.
SECURITY-3762 (1) / CVE-2026-57291 (missing permission check) & CVE-2026-57292 (CSRF) Gitee Plugin 1288.v18bdebc9069b and earlier does not perform permission checks in several HTTP endpoints implementing form validation for its global configuration.
This allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Additionally, these HTTP endpoints do not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.
SECURITY-3762 (2) / CVE-2026-57293 Gitee Plugin 1288.v18bdebc9069b and earlier does not correctly perform a permission check in an HTTP endpoint.
This allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins. Those can be used as part of an attack to capture the credentials using another vulnerability.
SECURITY-3774 / CVE-2026-57294 (missing permission check) & CVE-2026-57295 (CSRF) EC2 Fleet Plugin 4.2.3.539.v8fedff2a81c3 and earlier does not perform permission checks in several HTTP endpoints used to validate cloud configurations.
This allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing AWS credentials stored in Jenkins.
Additionally, these HTTP endpoints do not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.
SECURITY-3777 / CVE-2026-57296 External Workspace Manager Plugin 1.3.2 and earlier does not reject .. path segments when validating the custom workspace path provided to the exwsAllocate Pipeline step, allowing the resulting workspace path to escape the configured disk mount point.
This allows attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, which can lead to remote code execution.
SECURITY-3697 (1) / CVE-2026-57297 (missing permission check) & CVE-2026-57298 (CSRF) Contrast Continuous Application Security Plugin 3.11 and earlier does not perform a permission check in an HTTP endpoint that tests the connection to a Contrast TeamServer.
This allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, and service key.
Additionally, this HTTP endpoint does not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.
SECURITY-3697 (2) / CVE-2026-57299 Contrast Continuous Application Security Plugin 3.11 and earlier does not perform permission checks in several HTTP endpoints that fill list box options with the names of the configured Contrast metadata.
This allows attackers with Overall/Read permission to enumerate the names of configured Contrast metadata.
SECURITY-3649 / CVE-2026-57301 OWASP ZAP Plugin 1.0.7 and earlier does not support distributed builds, causing the file operations and build process of its "Automatically build ZAP" feature to be performed on the Jenkins controller rather than on the agent the build is assigned to.
This allows attackers with Item/Configure permission to configure the feature to build an attacker-controlled project, executing arbitrary code on the Jenkins controller and bypassing any restriction confining the build to a specific agent.
As of publication of this advisory, there is no fix.
SECURITY-3555 / CVE-2026-57302 FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller as part of its configuration.
These passwords can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
As of publication of this advisory, there is no fix.
SECURITY-3692 (1) / CVE-2026-57303 Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when parsing responses from the configured Assembla server.
This allows attackers able to control the responses of the configured Assembla server to extract secrets from the Jenkins controller or perform server-side request forgery.
As of publication of this advisory, there is no fix.
SECURITY-3692 (2) / CVE-2026-57304 (missing permission check) & CVE-2026-57305 (CSRF) Assembla Plugin 1.4 and earlier does not perform a permission check in an HTTP endpoint that tests the connection to an Assembla server.
This allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username and password.
Additionally, this HTTP endpoint does not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.
NOTE: This does not allow exploiting the XML external entity (XXE) vulnerability described in the previous advisory entry.
As of publication of this advisory, there is no fix.
SECURITY-3747 / CVE-2026-57306 (CSRF) & CVE-2026-57307 (missing permission check) Zowe zDevOps Plugin 1.1.3.50.ve350c9b450b1 and earlier does not perform a permission check in an HTTP endpoint implementing a connection test.
This allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Additionally, this HTTP endpoint does not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.
As of publication of this advisory, there is no fix.
-- CONFIDENTIALITY NOTICE: This email and any attachments contain confidential and proprietary information of CloudBees intended only for the named recipient(s). Unauthorized use or distribution is prohibited. If you received this in error, please notify the sender and delete this email.
A missing permission check in Jenkins Script Security Plugin 1399.ve6a66547f6e1 and earlier allows attackers with Overall/Read permission to enumerate pending and approved Script Security classpaths.
Jenkins is an open source automation server which enables developers around the world to reliably build, test, and deploy their software.
The following releases contain fixes for security vulnerabilities:
Credentials Binding Plugin 720.v3f6decef43ea GitHub Branch Source Plugin 1967.1969.v205fd594c821 GitHub Plugin 1.46.0.1 HTML Publisher Plugin 427.1 Matrix Authorization Strategy Plugin 3.2.10 Microsoft Entra ID (previously Azure AD) Plugin 667.v4c5827ae74a0 Script Security Plugin 1402.v94c9ce464861
Summaries of the vulnerabilities are below. More details, severity, and attribution can be found here: https://www.jenkins.io/security/advisory/2026-04-29/
We provide advance notification for security updates on this mailing list: https://groups.google.com/d/forum/jenkinsci-advisories
If you discover security vulnerabilities in Jenkins, please report them as described here: https://www.jenkins.io/security/#reporting-vulnerabilities
---
SECURITY-3662 / CVE-2026-42519 Script Security Plugin 1399.ve6a66547f6e1 and earlier does not perform a permission check in an HTTP endpoint.
This allows attackers with Overall/Read permission to enumerate pending and approved Script Security classpaths.
SECURITY-3672 / CVE-2026-42520 Credentials Binding Plugin 719.v80e905ef14eb and earlier does not sanitize file names for file and zip file credentials.
This allows attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem. If Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node, this can lead to remote code execution.
SECURITY-3676 / CVE-2026-42521 Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specified in configuration when deserializing inheritance strategies, without restricting the classes that can be instantiated.
This can be abused by attackers with Item/Configure permission to instantiate arbitrary types, which may lead to information disclosure or other impacts depending on the classes available on the classpath.
SECURITY-3702 / CVE-2026-42522 GitHub Branch Source Plugin 1967.vdead580c1aba and earlier does not perform a permission check in a method implementing form validation.
This allows attackers with Overall/Read permission to connect to an attacker-specified URL with attacker-specified GitHub App credentials.
SECURITY-3704 / CVE-2026-42523 GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling".
This results in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers with Overall/Read permission.
SECURITY-3706 / CVE-2026-42524 HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
SECURITY-3760 / CVE-2026-42525 Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login.
This allows attackers to perform phishing attacks by having users go to a Jenkins URL that will forward them to a different site after successful authentication.
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM.