Description
Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.
Published: 2026-08-05
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Jenkins Multijob Plugin versions 669.v9d96a_d9c71b_0 and earlier expose a Groovy scripting interface that does not integrate with the Script Security Plugin, allowing users with Item/Create or Item/Configure permissions to run arbitrary Groovy code inside the Jenkins controller JVM. This flaw gives the attacker full control over the Jenkins instance, enabling data exfiltration, configuration tampering, and complete system compromise, thus affecting confidentiality, integrity, and availability.

Affected Systems

Jenkins Multijob Plugin versions 669.v9d96a_d9c71b_0 and all earlier releases are affected. Any Jenkins deployment that has these plugin versions installed is at risk and should be evaluated for an upgrade.

Risk and Exploitability

An attacker who can create or configure a multijob project can exploit this vulnerability; no external network access is required – the attack is triggered purely by legitimate Jenkins user privileges. The CVSS score of 8.8 indicates high severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog. The attack vector is inferred from the supplied description, indicating an in‑Jenkins local privilege exploitation scenario.

Generated by OpenCVE AI on August 5, 2026 at 23:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Jenkins Multijob Plugin to the latest release where Groovy scripting is correctly integrated with the Script Security Plugin.
  • Restrict Item/Create and Item/Configure permissions for untrusted users or apply least‑privilege roles that disallow job configuration.
  • Ensure the Script Security Plugin is enabled and properly configured; add script approval rules to further harden the environment.

Generated by OpenCVE AI on August 5, 2026 at 23:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unrestricted Groovy Execution in Jenkins Multijob Plugin

Wed, 05 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via Groovy Script Execution in Jenkins Multijob Plugin Prior to v669
Weaknesses CWE-78

Wed, 05 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Multijob Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Multijob Plugin

Wed, 05 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via Groovy Script Execution in Jenkins Multijob Plugin Prior to v669
Weaknesses CWE-78

Wed, 05 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.
References

Subscriptions

Jenkins Project Jenkins Multijob Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-08-06T03:55:47.215Z

Reserved: 2026-08-04T14:13:20.602Z

Link: CVE-2026-70431

cve-icon Vulnrichment

Updated: 2026-08-05T18:24:53.110Z

cve-icon NVD

Status : Received

Published: 2026-08-05T18:17:12.773

Modified: 2026-08-06T05:17:06.537

Link: CVE-2026-70431

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T23:30:04Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')