CyberRota Analysis
AI-GeneratedThe Ivy Report Plugin for Jenkins, version 1.2 and earlier, is vulnerable to XML External Entity (XXE) attacks due to improper configuration of its XML parser when processing Ivy report files. This vulnerability could allow an attacker to exploit the XML parser, potentially leading to unauthorized data access or system compromise. Organizations using affected versions of Jenkins should prioritize patching this vulnerability to mitigate the risk of exploitation.
CVE
CVE-2026-70448
Severity
HIGH
CVSS
7.1
EPSS
0.19%
Jenkins
Original NVD Description
Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files.