Jenkins security advisory (AV26-877)
Brief
Serial Number: AV26-877
Date: September 3, 2026
As of September 2, 2026, Jenkins Project is affected by vulnerabilities in the following products:
- Jenkins
- ALL except 2.568.3
- ALL except 2.580
- Jenkins Allure Plugin
- Prior to or equal to 2.35.2
- Jenkins Customizable Header Plugin
- Prior to or equal to 295.v2544b_ca_19b_97
- Jenkins File Parameter Plugin
- Prior to or equal to 425.v3fa_801681b_5e
- Jenkins GitLab Plugin
- Prior to or equal to 1.9.16
- Jenkins LDAP Plugin
- Prior to or equal to 807.809.vd3a_4e5e4ec98
- Jenkins Microsoft Entra ID (previously Azure AD) Plugin
- Prior to or equal to 710.v0b_ff8e9cc2d2
- Jenkins Parameterized Remote Trigger Plugin
- Prior to or equal to 3.2.2
- Jenkins Performance Plugin
- Prior to or equal to 1015.v09ca_52b_3370e
- Jenkins Pipeline: Build Step Plugin
- Prior to or equal to 599.v4b_67ea_11b_152
- Jenkins SAML Plugin
- Prior to or
