XML External Entity Vulnerability in Jenkins Ivy Report Plugin
CVE-2026-70448

7.1HIGH

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
5 August 2026

What is CVE-2026-70448?

The Jenkins Ivy Report Plugin versions up to 1.2 are susceptible to an XML external entity (XXE) vulnerability, which arises from inadequate configuration of its XML parser. This oversight can lead to the processing of malicious Ivy report files, allowing attackers to exploit external entities and potentially expose sensitive data or cause unintended behavior within the application. Ensuring proper parser configuration is crucial to mitigating these risks and safeguarding your Jenkins environment.

Affected Version(s)

Jenkins Ivy Report Plugin 0 <= 1.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.