Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2657 articles · 156795 vulns · 36/41 feeds (7d)
← Back to list
EST
PRE-CVE
jenkins · jenkins plugins

Multiple Vulnerabilities in Jenkins Plugins

72% confidence

Description

Multiple security vulnerabilities have been identified in various Jenkins plugins including Active Directory Plugin, AppSpider Plugin, Bitbucket OAuth Plugin, buildgraph-view Plugin, Credentials Binding Plugin, Email Extension Plugin, GitHub Integration Plugin, Job Import Plugin, LDAP Plugin, Pipeline: Groovy Libraries Plugin, and Multijob Plugin. These affect versions prior to specified fixed versions and require updates to mitigate potential security risks.

Affected Products

VendorProductVersions
jenkinsjenkins pluginsActive Directory Plugin <= 2.4.1, AppSpider Plugin <= 1.0.17, Bitbucket OAuth Plugin <= 0.17, buildgraph-view Plugin <= 1.8, Credentials Binding Plugin <= 720.v3f6decef43ea_, Email Extension Plugin <= 1933.v45cec755423f, GitHub Integration Plugin <= 0.7.3, Job Import Plugin <= 143.v044a_2e819b_27, LDAP Plugin <= 807.v7d7de30930cf, Pipeline: Groovy Libraries Plugin <= 797.v90ea_a_9b_e45a_0, Multijob Plugin <= 662.vd2e0001f6b_b_d

Related News (1 articles)

Tier B
CCCS Canada1h ago
Jenkins security advisory (AV26-515)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
PublishedMay 27, 2026
Last enriched1h ago
Tags
jenkinspluginsecurity advisorymultiple vulnerabilities
Trending Score20
Source articles1
Independent1
Info Completeness5/14
Missing: cve_id, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-42524EXP
CVE-2026-42524: Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in
Trending: 1
CRITICALCVE-2026-42523EXP
CVE-2026-42523: Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing val
Trending: 1
HIGHCVE-2026-33002
Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expected
Trending: 1
MEDIUMCVE-2026-33003
Jenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or
Trending: 1
HIGHCVE-2026-42520EXP
CVE-2026-42520: Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file cre
Trending: 1

Pin to Dashboard

Verification

State: reported
Confidence: 72%

Vulnerability Timeline

CVE Published
May 27, 2026
Discovered by ZDM
May 27, 2026