Jenkins security advisory (AV26-877)
Canada's Cyber Centre relayed a Jenkins advisory (AV26-877) covering core and numerous plugin vulnerabilities fixed in 2.568.3/2.580.
The Canadian Centre for Cyber Security published advisory AV26-877 for the Jenkins security advisory dated September 2, 2026. Affected products include Jenkins releases other than 2.568.3 and 2.580, plus plugins such as GitLab, LDAP, Microsoft Entra ID, SAML, Script Security, Pipeline Build Step, and others. Administrators are encouraged to review the linked advisory and apply necessary updates.
- Jenkins core fixed in 2.568.3 and 2.580; all other releases affected
- Over a dozen plugins affected, including SAML, LDAP, Entra ID, and GitLab integrations
- Stems from the Jenkins Security Advisory published September 2, 2026
Full article205 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-877
Date: September 3, 2026
As of September 2, 2026, Jenkins Project is affected by vulnerabilities in the following products:
- Jenkins
- ALL except 2.568.3
- ALL except 2.580
- Jenkins Allure Plugin
- Prior to or equal to 2.35.2
- Jenkins Customizable Header Plugin
- Prior to or equal to 295.v2544b_ca_19b_97
- Jenkins File Parameter Plugin
- Prior to or equal to 425.v3fa_801681b_5e
- Jenkins GitLab Plugin
- Prior to or equal to 1.9.16
- Jenkins LDAP Plugin
- Prior to or equal to 807.809.vd3a_4e5e4ec98
- Jenkins Microsoft Entra ID (previously Azure AD) Plugin
- Prior to or equal to 710.v0b_ff8e9cc2d2
- Jenkins Parameterized Remote Trigger Plugin
- Prior to or equal to 3.2.2
- Jenkins Performance Plugin
- Prior to or equal to 1015.v09ca_52b_3370e
- Jenkins Pipeline: Build Step Plugin
- Prior to or equal to 599.v4b_67ea_11b_152
- Jenkins SAML Plugin
- Prior to or equal to 4.618.v441a_27fa_46d2
- Jenkins Script Security Plugin
- Prior to or equal to 1412.v7737b_3405f86
- Jenkins TICS Plugin
- Prior to or equal to 2025.1.1
- Jenkins ThinBackup Plugin
- Prior to or equal to 2.1.4
- Jenkins XebiaLabs XL Deploy Plugin
- Prior to or equal to 26.1.0
- Jenkins update-center2
- Prior to or equal to 3.18.3
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/jenkins-security-advisory-av26-877