CVE-2026-70431

Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-05 18:17

Updated : 2026-08-31 19:34


NVD link : CVE-2026-70431

Mitre link : CVE-2026-70431

CVE.ORG link : CVE-2026-70431


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')