Jenkins plugins Multiple Vulnerabilities (2026-09-02)

high Nessus Plugin ID 342361

Synopsis

An application running on a remote web server host is affected by multiple vulnerabilities

Description

According to their self-reported version numbers, the version of Jenkins plugins running on the remote web server are affected by multiple vulnerabilities:

- Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance configuration through Stapler data binding, allowing attackers to configure a custom SVG icon containing inline JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability.
(CVE-2026-84673)

- Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled content and authenticate as any user. (CVE-2026-84668)

- Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group. (CVE-2026-84672)

- Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. (CVE-2026-84674)

- Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. (CVE-2026-84676)

- Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names, descriptions, and version metadata) on plugin download index pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting.
(CVE-2026-84677)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update Jenkins plugins to the following versions:
- Allure Plugin to version 2.36.0 or later
- Customizable Header Plugin to version 330.v8a_8d87511ea_1 or later
- File Parameter Plugin to version 433.va_0b_80359d54d or later
- GitLab Plugin to version 1.9.182144.vc1c369226a_52 or later
- Job Configuration History Plugin to version 1380.v762185b_9a_793 or later
- LDAP Plugin to version 825.v2fca_37dd5b_cb_ or later
- Microsoft Entra ID (previously Azure AD) Plugin to version 711.v34046f788fd7 or later
- Parameterized Remote Trigger Plugin: See vendor advisory
- Performance Plugin to version 1017.v9e9f7b_b_b_c5e7 or later
- Pipeline: Build Step Plugin to version 601.v6d4c6d1a_9dc7 or later
- Pipeline: Groovy Libraries Plugin to version 805.va_fc79344957d or later
- SAML Plugin to version 4.623.v7875d61cd9f5 or later
- Script Security Plugin to version 1415.v9a_f9b_3a_c253d or later
- SonarQube Scanner Plugin to version 2.19.0 or later
- ThinBackup Plugin to version 2.1.5 or later
- TICS Plugin to version 2026.1.0 or later
- XebiaLabs XL Deploy Plugin to version 26.3.0 or later

See vendor advisory for more details.

See Also

https://jenkins.io/security/advisory/2026-09-02

Plugin Details

Severity: High

ID: 342361

File Name: jenkins_security_advisory_2026-09-02_plugins.nasl

Version: 1.1

Type: Combined

Agent: windows, macosx, unix

Family: CGI abuses

Published: 9/2/2026

Updated: 9/2/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Enable CGI Scanning: true

Risk Information

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-84673

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:cloudbees:jenkins, cpe:/a:jenkins:jenkins

Required KB Items: installed_sw/Jenkins

Exploit Ease: No known exploits are available

Patch Publication Date: 9/2/2026

Vulnerability Publication Date: 9/2/2026

Reference Information

CVE: CVE-2026-84645, CVE-2026-84653, CVE-2026-84658, CVE-2026-84659, CVE-2026-84660, CVE-2026-84661, CVE-2026-84662, CVE-2026-84663, CVE-2026-84664, CVE-2026-84665, CVE-2026-84666, CVE-2026-84667, CVE-2026-84668, CVE-2026-84669, CVE-2026-84670, CVE-2026-84671, CVE-2026-84672, CVE-2026-84673, CVE-2026-84674, CVE-2026-84675, CVE-2026-84676, CVE-2026-84677