CVE-2020-2261: Jenkins Perfecto

High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Jenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Configure permission to run arbitrary commands on the Jenkins controller

Affected products

  • Jenkins Perfecto: up to and including 1.17

Published 2020-09-16. Last modified 2026-06-17.