CVE-2026-70439
Received
Received - Intake
Jenkins XML Job to Job DSL Plugin Permission Bypass
Vulnerability report for CVE-2026-70439, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-05
Last updated on: 2026-08-05
Assigner: Jenkins Project
Description
Description
Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appropriate permissions to invoke the conversion functionality.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| jenkinsci | xml_job_to_job_dsl_plugin | to 0.1.14 (exc) |
| jenkinsci | xml_job_to_job_dsl_plugin | to 0.1.13 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |