Jenkins plugins Multiple Vulnerabilities (2026-08-05)

critical Nessus Plugin ID 332686

Synopsis

An application running on a remote web server host is affected by multiple vulnerabilities

Description

According to their self-reported version numbers, the version of Jenkins plugins running on the remote web server are affected by multiple vulnerabilities:

- In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2...
(CVE-2026-70426)

- Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting...
(CVE-2026-70428)

- A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with...
(CVE-2026-70435)

- Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check ...
(CVE-2026-70436)

- Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a...
(CVE-2026-70437)

- Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing...
(CVE-2026-70439)

- Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate...
(CVE-2026-70443)

- A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier...
(CVE-2026-70444)

- Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with...
(CVE-2026-70447)

- Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML...
(CVE-2026-70448)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update Jenkins plugins to the following versions:
- AWS CodeBuild Plugin: See vendor advisory
- CodeSonar Plugin: See vendor advisory
- External Workspace Manager Plugin to version 1.4.2 or later
- Google Chat Notification Plugin: See vendor advisory
- HCL AppScan Plugin to version 1.8.4 or later
- Horreum Plugin: See vendor advisory
- Ivy Report Plugin: See vendor advisory
- Multijob Plugin to version 677.v7ffc23d6a_4c2 or later
- Parameterized Remote Trigger Plugin: See vendor advisory
- Qualys Container Scanning Connector Plugin: See vendor advisory
- Sauce OnDemand Plugin: See vendor advisory
- SCM-Manager Plugin to version 1.12.1 or later
- Summary Display Plugin: See vendor advisory
- Violation Comments to GitLab Plugin: See vendor advisory
- Webhook Secret Credentials Provider Plugin to version 32.v09c9b_522f0a_8 or later
- XML Job to Job DSL Plugin: See vendor advisory

See vendor advisory for more details.

See Also

https://jenkins.io/security/advisory/2026-08-05

Plugin Details

Severity: Critical

ID: 332686

File Name: jenkins_security_advisory_2026-08-05_plugins.nasl

Version: 1.1

Type: Combined

Agent: windows, macosx, unix

Family: CGI abuses

Published: 8/5/2026

Updated: 8/5/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Enable CGI Scanning: true

Risk Information

VPR

Risk Factor: High

Score: 7.7

Percentile: 99.03

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-70441

CVSS v3

Risk Factor: Critical

Base Score: 9

Temporal Score: 7.8

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-70426

Vulnerability Information

CPE: cpe:/a:cloudbees:jenkins, cpe:/a:jenkins:jenkins

Required KB Items: installed_sw/Jenkins

Exploit Ease: No known exploits are available

Patch Publication Date: 8/5/2026

Vulnerability Publication Date: 8/5/2026

Reference Information

CVE: CVE-2026-70426, CVE-2026-70427, CVE-2026-70428, CVE-2026-70431, CVE-2026-70432, CVE-2026-70433, CVE-2026-70434, CVE-2026-70435, CVE-2026-70436, CVE-2026-70437, CVE-2026-70438, CVE-2026-70439, CVE-2026-70440, CVE-2026-70441, CVE-2026-70442, CVE-2026-70443, CVE-2026-70444, CVE-2026-70445, CVE-2026-70446, CVE-2026-70447, CVE-2026-70448