AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-70448

HIGH · CVSS 7.1 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Ivy Report Plugin for Jenkins, version 1.2 and earlier, is vulnerable to XML External Entity (XXE) attacks due to improper configuration of its XML parser when processing Ivy report files. This vulnerability could allow an attacker to exploit the XML parser, potentially leading to unauthorized data access or system compromise. Organizations using affected versions of Jenkins should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-70448
Severity
HIGH
CVSS
7.1
EPSS
0.19%
Jenkins

Original NVD Description

Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files.