logo

Critical Jenkins Flaws Expose CI/CD Servers to Remote Code Execution

ID: 6a651f22-6ff7-5749-aa0e-fbfa79b72473

STIX ID: report--6a651f22-6ff7-5749-aa0e-fbfa79b72473

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-19

Date Updated: 2026-04-23

Author: Ddos

...
...

*Executive summary:* A critical Jenkins security advisory describes two high-severity core vulnerabilities (CVE-2026-33001: arbitrary file creation via unsafe symlink handling during archive extraction enabling RCE; CVE-2026-33002: CLI WebSocket origin-check bypass enabling DNS rebinding-based remote command execution) and plugin issues (CVE-2026-33003/33004: LoadNinja plugin storing API keys unencrypted and exposing them via job config or web UI). Administrators are urged to update Jenkins and the plugin immediately and apply mitigations such as tightening anonymous permissions and enabling authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.