Description
Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appropriate permissions to invoke the conversion functionality.
Published: 2026-08-05
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Jenkins XML Job to Job DSL Plugin allows a user without proper permissions to invoke the conversion functionality. This represents an improper authorization failure, allowing unauthorized modification or creation of job definitions within the Jenkins instance. The issue is identified as a permission check omission (CWE‑862).

Affected Systems

Jenkins installations that include the XML Job to Job DSL Plugin version 0.1.13 or earlier are affected. Application of the plugin beyond this version is not known to be impacted by this issue.

Risk and Exploitability

Based on the description, it is inferred that attackers can trigger the conversion endpoint remotely via HTTP/HTTPS requests if they can reach the Jenkins server. The CVSS score of 6.5 indicates medium severity; the EPSS score is not listed. The vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed exploitation at present. Still, the capability to alter job configurations without authorization represents a significant security risk for exposed Jenkins instances.

Generated by OpenCVE AI on August 5, 2026 at 23:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the XML Job to Job DSL Plugin to the latest release (≥0.1.14) which includes proper permission checks.
  • If an upgrade cannot occur immediately, block external access to the plugin’s conversion URL or restrict it to authenticated roles only via Jenkins security settings.
  • Ensure Jenkins requires authentication for all endpoints and that users do not have permissions to invoke the conversion functionality.

Generated by OpenCVE AI on August 5, 2026 at 23:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Xml Job To Job Dsl Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Xml Job To Job Dsl Plugin

Wed, 05 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Jenkins XML Job to Job DSL Plugin Improper Permission Check Allows Unauthorized Job Conversion

Wed, 05 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Jenkins XML Job to Job DSL Plugin Unauthorized Conversion Due to Missing Permission Checks
Weaknesses CWE-285

Wed, 05 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Jenkins XML Job to Job DSL Plugin Unauthorized Conversion Due to Missing Permission Checks
Weaknesses CWE-285
CWE-862
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appropriate permissions to invoke the conversion functionality.
References

Subscriptions

Jenkins Project Jenkins Xml Job To Job Dsl Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-08-05T19:40:18.173Z

Reserved: 2026-08-04T14:13:20.602Z

Link: CVE-2026-70439

cve-icon Vulnrichment

Updated: 2026-08-05T19:40:09.795Z

cve-icon NVD

Status : Received

Published: 2026-08-05T18:17:13.713

Modified: 2026-08-05T20:17:14.957

Link: CVE-2026-70439

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:05:31Z

Weaknesses