Vendor
Jenkins vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 66 vulnerabilities in Jenkins: 0 in the last 7 days and 43 in the last 90 days, 7 of them critical and 6 exploited in the wild. The most recent, CVE-2026-92141, was published on 16 September 2026. 5 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 43
- Critical, all time
- 7
- Exploited in the wild
- 6
About Jenkins
An open-source automation and continuous integration/continuous delivery platform.
Jenkins technologies
Latest Jenkins vulnerabilities
- CVE-2026-92141: Jenkins Keycloak Authentication Plugin open redirect after loginmediumCVSS 4.3EPSS 0.3%
- CVE-2026-92138: Jenkins Bitbucket Server Integration Plugin OAuth hijackingmediumCVSS 4.2EPSS 0.1%
- CVE-2026-92137: Jenkins Robot Framework Plugin path traversal in archive directoryhighCVSS 8.8EPSS 0.8%
- CVE-2026-92135: Jenkins Coverage Plugin stored XSS via coverage results ID validation bypasshighCVSS 8EPSS 0.4%
- CVE-2026-92134: Jenkins Warnings Plugin stored XSS via analysis results IDhighCVSS 8EPSS 0.4%
- CVE-2026-92131: Jenkins Pipeline: Groovy Libraries Plugin path traversalmediumCVSS 4.2EPSS 0.2%
- CVE-2026-92130: Jenkins Pipeline: Multibranch Plugin credentials context bypasslowCVSS 3.1EPSS 0.2%
- CVE-2026-92129: Jenkins Script Security Plugin sandbox bypass with dynamic methodshighCVSS 7.5EPSS 0.5%
- CVE-2026-92128: Jenkins Script Security Plugin arbitrary JAR loading via double downloadhighCVSS 7.5EPSS 0.3%
- CVE-2026-92127: Jenkins Script Security Plugin classpath approval bypasshighCVSS 8EPSS 0.6%
- CVE-2026-92126: Jenkins Script Security Plugin sandbox bypass via @Builder annotationhighCVSS 8.5EPSS 0.5%
- CVE-2026-92125: Jenkins Script Security Plugin sandbox bypass via @GroovyASTTransformationClasshighCVSS 8.8EPSS 0.6%
- CVE-2026-92124: Jenkins Script Security Plugin sandbox bypass in collection castinghighCVSS 8.8EPSS 0.6%
- CVE-2026-92123: Jenkins Script Security Plugin sandbox bypass on null operationshighCVSS 8.8EPSS 0.6%
- CVE-2026-92122: Jenkins Script Security Plugin sandbox bypass via proxy method coercionhighCVSS 8.8EPSS 0.6%
- CVE-2026-84677: Jenkins update-center2 stored XSS in plugin metadatamediumCVSS 5.4EPSS 0.2%
- CVE-2026-84676: Jenkins Parameterized Remote Trigger Plugin unencrypted token storagemediumCVSS 4.3EPSS 0.2%
- CVE-2026-84675: Jenkins TICS Plugin OS command injection via build environment variablehighCVSS 7.4EPSS 1.2%
- CVE-2026-84673: Jenkins Customizable Header Plugin stored XSS in icon configurationhighCVSS 8.8EPSS 0.5%
- CVE-2026-84672: Jenkins Microsoft Entra ID Plugin privilege escalation via group name collisionhighCVSS 8.8EPSS 0.4%
- CVE-2026-84671: Jenkins File Parameter Plugin arbitrary file write to RCEhighCVSS 8.8EPSS 0.8%
- CVE-2026-84670: Jenkins Performance Plugin unsafe deserializationhighCVSS 8.8EPSS 0.6%
- CVE-2026-84669: Jenkins Allure Plugin path traversal in report retrievalhighCVSS 8.8EPSS 0.5%
- CVE-2026-84668: Jenkins SAML Plugin metadata file overwrite via Stapler bindinghighCVSS 8.8EPSS 0.4%
- CVE-2026-84667: Jenkins ThinBackup Plugin backup configuration overwrite via Stapler bindinghighCVSS 7.1EPSS 0.4%
Most severe Jenkins vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2024-23897: Arbitrary file read vulnerability through the Jenkins CLI can lead to RCEcriticalexploited in the wildCVSS 3.1EPSS 100.0%
- CVE-2019-1003030: Sandbox bypass in Jenkins Pipeline: Groovy Plugincriticalexploited in the wildCVSS 3.1EPSS 96.9%
- CVE-2019-1003029: Sandbox bypass in Script Security Plugincriticalexploited in the wildCVSS 3.1EPSS 73.9%
- CVE-2015-5317: Jenkins discloses project names via fingerprintscriticalexploited in the wildCVSS 3.1EPSS 23.0%
- CVE-2017-1000353: Deserialization of Untrusted Data in Jenkinscriticalexploited in the wildCVSS 3EPSS 99.7%
- CVE-2018-1000861: Deserialization of Untrusted Data in Jenkinscriticalexploited in the wildCVSS 3EPSS 98.3%
- CVE-2016-9299: Jenkins remoting module Java deserialization RCE via LDAP querycriticalCVSS 9.8EPSS 96.9%
- CVE-2026-53435: Jenkins arbitrary type deserialization in config.xml processinghighCVSS 8.8EPSS 2.2%
- CVE-2026-92137: Jenkins Robot Framework Plugin path traversal in archive directoryhighCVSS 8.8EPSS 0.8%
- CVE-2026-84671: Jenkins File Parameter Plugin arbitrary file write to RCEhighCVSS 8.8EPSS 0.8%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 28 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 15 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/jenkins.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Jenkins vulnerabilities", https://junglewise.ai/threats/vendors/jenkins, 28 September 2026.