CyberRota Analysis
AI-GeneratedThe XML Job to Job DSL Plugin in Jenkins versions 0.1.13 and earlier is vulnerable due to the absence of permission checks, enabling unauthorized users to access and invoke the conversion functionality. This flaw could lead to unauthorized modifications or execution of jobs, potentially compromising the integrity of the CI/CD pipeline. Organizations using affected versions of Jenkins should prioritize remediation to mitigate the risk of exploitation.
CVE
CVE-2026-70439
Severity
MEDIUM
CVSS
6.5
EPSS
0.16%
Jenkins
Original NVD Description
Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appropriate permissions to invoke the conversion functionality.