AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-70439

MEDIUM · CVSS 6.5 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The XML Job to Job DSL Plugin in Jenkins versions 0.1.13 and earlier is vulnerable due to the absence of permission checks, enabling unauthorized users to access and invoke the conversion functionality. This flaw could lead to unauthorized modifications or execution of jobs, potentially compromising the integrity of the CI/CD pipeline. Organizations using affected versions of Jenkins should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-70439
Severity
MEDIUM
CVSS
6.5
EPSS
0.16%
Jenkins

Original NVD Description

Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appropriate permissions to invoke the conversion functionality.