CVE-2026-9674
Received
Received - Intake
CSRF in Jenkins Multijob Plugin
Publication date: 2026-05-27
Last updated on: 2026-05-27
Assigner: Jenkins Project
Description
Description
A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows attackers to resume failed Multijob builds.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| jenkinsci | multijob_plugin | 662.vd2e0001f6b_b_d |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a cross-site request forgery (CSRF) issue found in the Jenkins Multijob Plugin version 662.vd2e0001f6b_b_d and earlier. It allows attackers to resume failed Multijob builds without proper authorization.
How can this vulnerability impact me? :
An attacker exploiting this vulnerability could resume failed Multijob builds in Jenkins without permission. This could lead to unauthorized execution of build jobs, potentially disrupting build processes or causing unintended actions within the Jenkins environment.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70