AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-70431

HIGH · CVSS 8.8 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Jenkins Multijob Plugin versions up to 669.v9d96a_d9c71b_0 are vulnerable due to insufficient integration with the Script Security Plugin, enabling attackers with Item/Create or Item/Configure permissions to execute arbitrary Groovy scripts on the Jenkins controller JVM. This vulnerability poses a significant risk as it allows unauthorized code execution, potentially compromising the entire Jenkins environment. Organizations using affected versions of Jenkins should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-70431
Severity
HIGH
CVSS
8.8
EPSS
0.37%
Jenkins

Original NVD Description

Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.