CVE-2026-70431

Jenkins · Multijob Plugin

A security vulnerability in the Jenkins Multijob Plugin allows for unauthorized actions or information disclosure, affecting versions up to 669.v9d96a_d9c71b_0.

Executive summary

A high-severity vulnerability in the Jenkins Multijob Plugin could allow authenticated attackers to gain unauthorized access or influence system operations.

Vulnerability

The vulnerability exists within the Jenkins Multijob Plugin and requires the attacker to have authenticated access to the Jenkins environment. It allows for potential unauthorized actions due to insufficient security controls within the plugin functions.

Business impact

With a CVSS score of 8.8, this flaw represents a significant risk to the integrity and availability of CI/CD pipelines. Exploitation could allow an attacker to disrupt development workflows, inject malicious code into build processes, or access sensitive build artifacts, leading to potential supply chain compromise.

Remediation

Immediate Action: Review the official Jenkins security advisory and apply the recommended plugin update or configuration change.

Proactive Monitoring: Monitor Jenkins audit logs for unusual job executions or configuration changes initiated by unexpected user accounts.

Compensating Controls: Implement strict Role-Based Access Control (RBAC) within Jenkins to limit the number of users who can interact with the Multijob Plugin and associated job configurations.

Exploitation status

Public Exploit Available: No confirmed public exploit available.

Analyst recommendation

Jenkins administrators should treat this vulnerability with high urgency given the potential for CI/CD pipeline compromise. Ensure the Multijob Plugin is updated to the latest secure version once available.