Jenkins security advisory (AV26-877)

Serial Number: AV26-877
Date: September 3, 2026

As of September 2, 2026, Jenkins Project is affected by vulnerabilities in the following products:

  • Jenkins
    • ALL except 2.568.3
    • ALL except 2.580
  • Jenkins Allure Plugin
    • Prior to or equal to 2.35.2
  • Jenkins Customizable Header Plugin
    • Prior to or equal to 295.v2544b_ca_19b_97
  • Jenkins File Parameter Plugin
    • Prior to or equal to 425.v3fa_801681b_5e
  • Jenkins GitLab Plugin
    • Prior to or equal to 1.9.16
  • Jenkins LDAP Plugin
    • Prior to or equal to 807.809.vd3a_4e5e4ec98
  • Jenkins Microsoft Entra ID (previously Azure AD) Plugin
    • Prior to or equal to 710.v0b_ff8e9cc2d2
  • Jenkins Parameterized Remote Trigger Plugin
    • Prior to or equal to 3.2.2
  • Jenkins Performance Plugin
    • Prior to or equal to 1015.v09ca_52b_3370e
  • Jenkins Pipeline: Build Step Plugin
    • Prior to or equal to 599.v4b_67ea_11b_152
  • Jenkins SAML Plugin
    • Prior to or equal to 4.618.v441a_27fa_46d2
  • Jenkins Script Security Plugin
    • Prior to or equal to 1412.v7737b_3405f86
  • Jenkins TICS Plugin
    • Prior to or equal to 2025.1.1
  • Jenkins ThinBackup Plugin
    • Prior to or equal to 2.1.4
  • Jenkins XebiaLabs XL Deploy Plugin
    • Prior to or equal to 26.1.0
  • Jenkins update-center2
    • Prior to or equal to 3.18.3

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Date modified: