Permission Check Bypass in Jenkins XML Job to Job DSL Plugin
CVE-2026-70439
Currently unrated
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-70439?
The Jenkins XML Job to Job DSL Plugin allows attackers without proper permissions to exploit a flaw that bypasses necessary permission checks. This issue can lead to unauthorized users invoking the plugin’s conversion functionality, which could compromise the integrity of the Jenkins environment. Users are strongly advised to upgrade to the latest version to mitigate this vulnerability.
Affected Version(s)
Jenkins XML Job to Job DSL Plugin 0 <= 0.1.13