In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier,...
High severity
Unreviewed
Published
Sep 2, 2026
to the GitHub Advisory Database
•
Updated Sep 2, 2026
Description
Published by the National Vulnerability Database
Sep 2, 2026
Published to the GitHub Advisory Database
Sep 2, 2026
Last updated
Sep 2, 2026
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field values in user-submitted
config.xmldocuments and subsequently handle HTTP requests via Stapler, resulting in remote code execution.References