CVE-2026-70439: Jenkins Project Jenkins XML Job To Job DSL Plugin
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appropriate permissions to invoke the conversion functionality.
Affected products
- Jenkins Project Jenkins XML Job To Job DSL Plugin: up to and including 0.1.13
Published 2026-08-05. Last modified 2026-08-31.