CVE-2026-27099Patch(jenkins / jenkins)

LOWCVSS 8.0 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch jenkins jenkins systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure or Agent/Disconnect permission.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jenkins

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 15 mentions across 6 observed days
  • Momentum state: declining

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 12 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 5 mentions (2026-02-20); latest day: 1
  • 15 total mentions across 6 days

Affected systems

Vendors
Products
jenkins

Deep dive

Activity timeline15 mentions / 6d
01345Mentions · 2026-02-18: 4Mentions · 2026-02-19: 3Mentions · 2026-02-20: 5Mentions · 2026-02-23: 1Mentions · 2026-02-27: 1Mentions · 2026-05-29: 1PoC Mentioned / Linked · 2026-05-29: 1Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-02-19: 2Patch / Workaround · 2026-02-20: 4Patch / Workaround · 2026-02-23: 1Patch / Workaround · 2026-02-27: 1Technical Details · 2026-02-18: 2Technical Details · 2026-02-19: 3Technical Details · 2026-02-20: 4Technical Details · 2026-02-23: 1Technical Details · 2026-02-27: 1Technical Details · 2026-05-29: 102-1802-1902-2002-2302-2705-29
Signal classification4 categories
Patch
960.0%
General
320.0%
Disclosure
213.3%
PoC
16.7%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-02-184
General3Patch1
2026-02-193
Patch3
2026-02-205
Disclosure2Patch3
2026-02-231
Patch1
2026-02-271
Patch1
2026-05-291
PoC1
Full discourse15 posts
  • Open Source Security mailing list@oss_security
    Patch

    Multiple vulnerabilities in Jenkins https://www.openwall.com/lists/oss-security/2026/02/18/4 Fixed in 2.551 and LTS 2.541.2 CVE-2026-27099 "Mark temporarily offline" stored XSS exploitable by attackers with Agent/Configure or Agent/Disconnect permission CVE-2026-27100 Run Parameter information disclosure

    Post summary

    Multiple Jenkins vulnerabilities (CVE-2026-27099 and CVE-2026-27100) have been disclosed; patches are available in version 2.551 and LTS 2.541.2.

    00042340
    4.4K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Jenkins の脆弱性 CVE-2026-27099/27100 が FIX:ビルド環境が XSS 攻撃の標的に https://iototsecnews.jp/2026/02/20/critical-jenkins-flaw-exposes-build-environments-to-xss-attacks/ CI/CD パイプラインの心臓部である Jenkins において、管理者権限の奪取や内部情報の偵察につながる 2 件の脆弱性が修正されました。最も危険なのは、エージェント・ノードのオフライン原因を処理する際にトリガーされる脆弱性 CVE-2026-27099 です。Jenkins には、ノードを切り離す際に管理者が理由をメモする機能がありますが、この入力内容が適切に無害化されず、そのまま HTML として実行されてしまう設計になっていました。もう 1 つの脆弱性 CVE-2026-27100 は、本来は見ることができないはずの “ビルドの存在や名称” を、パラメータを通じて外部から推測/特定できてしまうという情報漏洩の問題です。これらの不備は、ソフトウェア開発の自動化プロセスそのものを攻撃の拠点に変えてしまうリスクを秘めています。ご利用のチームは、ご注意ください。 #CVE202627099 #CVE202627100 #Jenkins #Vulnerability

    Post summary

    The article reports that two Jenkins CVEs (CVE-2026-27099 and CVE-2026-27100) have been patched, detailing XSS and information‑leakage flaws while urging teams to remain alert.

    01000154
    485 followersView on X
  • protect_cyber_sec@AmirHossein_sec
    Patch

    به تازگی برای Jenkins ، آسیب پذیری جدیدی با کد شناسایی CVE-2026-27099 از نوع XSS منتشر شده است. این آسیب پذیری xss از نوع Store XSS می باشد. برای پیشگیری و مقابله به نسخه های 2.551 و 2.541.2 به روز رسانی نمایید. https://tosinso.com/instructors/8bd4fef4-b53e-4dc0-8120-f8630fa08cc2#courses-section https://t.co/9GPFPlY9gS

    Post summary

    The post announces a store‑type XSS vulnerability (CVE‑2026‑27099) in Jenkins and recommends updating to versions 2.551 and 2.541.2 for mitigation, with no evidence of exploitation or PoC.

    0001042
    206 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Jenkins patches a high-severity stored XSS flaw (CVE-2026-27099) and an info disclosure bug. Update to version 2.551 or LTS 2.541.2 to secure pipelines. #Jenkins #DevOps #CyberSecurity #CVE #XSS #InfoSec #PatchAlert https://securityonline.info/ci-cd-at-risk-high-severity-jenkins-xss-flaw-exposes-build-environments/

    Post summary

    Jenkins reported a high‑severity stored XSS vulnerability (CVE‑2026‑27099) and an info disclosure bug, advising users to update to version 2.551 or LTS 2.541.2 to secure pipelines.

    00010214
    10.3K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27099 Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offl… https://www.cve.org/CVERecord?id=CVE-2026-27099

    Post summary

    The text identifies Jenkins versions affected by CVE‑2026‑27099 and provides a link to the CVE record, but offers no further technical, exploit, or mitigation details.

    00001125
    56.4K followersView on X
  • CyberGuider@CyberGuider
    PoC

    Writeup for CVE-2026-27099 Jenkins XSS lab testing @ https://www.cyberguider.com/stored-cross-site-scripting-injection-in-jenkins-2-528-2-cve-2026-27099/

    Post summary

    The post points to a writeup that includes a proof‑of‑concept for the stored XSS vulnerability in Jenkins (CVE‑2026‑27099), giving technical details but lacking exploit code, patch info, or evidence of active exploitation.

    0000062
    198 followersView on X
  • CinchOps@CinchOpsIT
    Patch

    🚨 𝗗𝗲𝘃𝗲𝗹𝗼𝗽𝗲𝗿𝘀 𝗮𝗻𝗱 𝗜𝗧 𝗧𝗲𝗮𝗺𝘀 - 𝗨𝗽𝗱𝗮𝘁𝗲 𝗝𝗲𝗻𝗸𝗶𝗻𝘀 𝗡𝗼𝘄 If your business uses Jenkins for software builds or CI/CD pipelines, two new vulnerabilities were just disclosed that need immediate attention. The most serious one - CVE-2026-27099 - is a stored cross-site scripting flaw. An attacker with basic access can inject malicious JavaScript that runs whenever other users view the affected agent's status page. That means session hijacking and credential theft from inside your own build environment. 𝗧𝗵𝗲 𝗽𝗮𝘁𝗰𝗵 𝗶𝘀 𝗮𝗹𝗿𝗲𝗮𝗱𝘆 𝗼𝘂𝘁 - 𝗝𝗲𝗻𝗸𝗶𝗻𝘀 𝟮.𝟱𝟱𝟭 𝗮𝗻𝗱 𝗟𝗧𝗦 𝟮.𝟱𝟰𝟭.𝟮 𝗳𝗶𝘅 𝗯𝗼𝘁𝗵 𝗶𝘀𝘀𝘂𝗲𝘀. ​̲𝗨​̲𝗻​̲𝗽​̲𝗮​̲𝘁​̲𝗰​̲𝗵​̲𝗲​̲𝗱​̲ ​̲𝘀​̲𝗼​̲𝗳​̲𝘁​̲𝘄​̲𝗮​̲𝗿​̲𝗲​̲ ​̲𝗶​̲𝗻​̲ ​̲𝘆​̲𝗼​̲𝘂​̲𝗿​̲ ​̲𝗱​̲𝗲​̲𝘃​̲𝗲​̲𝗹​̲𝗼​̲𝗽​̲𝗺​̲𝗲​̲𝗻​̲𝘁​̲ ​̲𝗲​̲𝗻​̲𝘃​̲𝗶​̲𝗿​̲𝗼​̲𝗻​̲𝗺​̲𝗲​̲𝗻​̲𝘁​̲ ​̲𝗶​̲𝘀​̲𝗻​̲'​̲𝘁​̲ ​̲𝗷​̲𝘂​̲𝘀​̲𝘁​̲ ​̲𝗮​̲ ​̲𝗱​̲𝗲​̲𝘃​̲𝗲​̲𝗹​̲𝗼​̲𝗽​̲𝗲​̲𝗿​̲ ​̲𝗽​̲𝗿​̲𝗼​̲𝗯​̲𝗹​̲𝗲​̲𝗺​̲.​̲ ​̲𝗜​̲𝘁​̲'​̲𝘀​̲ ​̲𝗮​̲ ​̲𝗯​̲𝘂​̲𝘀​̲𝗶​̲𝗻​̲𝗲​̲𝘀​̲𝘀​̲ ​̲𝗿​̲𝗶​̲𝘀​̲𝗸​̲.​̲ ​̲𝗢​̲𝗻​̲𝗲​̲ ​̲𝗵​̲𝗶​̲𝗷​̲𝗮​̲𝗰​̲𝗸​̲𝗲​̲𝗱​̲ ​̲𝗱​̲𝗲​̲𝘃​̲ ​̲𝘀​̲𝗲​̲𝘀​̲𝘀​̲𝗶​̲𝗼​̲𝗻​̲ ​̲𝗰​̲𝗮​̲𝗻​̲ ​̲𝗲​̲𝘅​̲𝗽​̲𝗼​̲𝘀​̲𝗲​̲ ​̲𝗔​̲𝗣​̲𝗜​̲ ​̲𝗸​̲𝗲​̲𝘆​̲𝘀​̲,​̲ ​̲𝗱​̲𝗮​̲𝘁​̲𝗮​̲𝗯​̲𝗮​̲𝘀​̲𝗲​̲ ​̲𝗰​̲𝗼​̲𝗻​̲𝗳​̲𝗶​̲𝗴​̲𝘀​̲,​̲ ​̲𝗮​̲𝗻​̲𝗱​̲ ​̲𝘀​̲𝗼​̲𝘂​̲𝗿​̲𝗰​̲𝗲​̲ ​̲𝗰​̲𝗼​̲𝗱​̲𝗲​̲. ❓ Does your IT team have a process for patching developer tools, not just end-user software? If you're not sure, that's worth a conversation. 📲 CinchOps handles patch management for Houston businesses so nothing falls through the cracks. Contact us today. 🌐 http://cinchops.com/contact | 📲 281‑269‑6506 Full Article: https://cybersecuritynews.com/jenkins-vulnerability-exposes-xss-attacks/ #HoustonBusiness #KatyTX #ManagedIT #ITSupport #Cybersecurity

    Post summary

    The post announces a stored XSS vulnerability (CVE‑2026‑27099) in Jenkins and informs readers that patches (Jenkins 2.551 and LTS 2.541.2) are already available, urging prompt application.

    0000036
    3 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos Jenkins ❗ CVE-2026-27099 ➡️ Más info: https://www.cert.gov.py/vulnerabilidaden-productos-jenkins/ https://t.co/NUU7PpVikV

    Post summary

    A new CVE-2026-27099 vulnerability affecting Jenkins products has been announced, with a link provided for further information.

    0000091
    6.6K followersView on X
  • protect_cyber_sec@AmirHossein_sec
    Patch

    به تازگی برای Jenkins ، آسیب پذیری جدیدی با کد شناسایی CVE-2026-27099 از نوع XSS منتشر شده است. این آسیب پذیری xss از نوع Store XSS می باشد. برای پیشگیری و مقابله به نسخه های 2.551 و 2.541.2 به روز رسانی نمایید. https://tosinso.com/instructors/8bd4fef4-b53e-4dc0-8120-f8630fa08cc2#courses-section https://t.co/EEfVFBrIzU

    Post summary

    The post announces a Store XSS vulnerability in Jenkins (CVE-2026-27099) and directs users to update to specific patched versions, providing technical detail but no PoC, exploit code, or evidence of active exploitation.

    0000041
    206 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    Jenkins Core hit by critical stored XSS flaw CVE-2026-27099 exposing build environments, plus CVE-2026-27100, disclosed by the European Commission under the Jenkins Bug Bounty. Admins should plan fixes. #XSS https://threatcluster.io/cluster/critical-jenkins-vulnerability-exposes-build-environments-to-23a07ce9

    Post summary

    Jenkins Core is vulnerable to critical stored XSS (CVE-2026-27099 and CVE-2026-27100), exposing build environments; administrators are urged to plan and apply fixes.

    0000048
    71 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Critical Jenkins Core Bugs: Stored XSS + Build Info Leak Fixed in 2.551 / LTS 2.541.2 Jenkins disclosed two core flaws: CVE-2026-27099 (high) stored XSS via unescaped “node offline cause description” allowing users with Agent/Configure or Agent/Disconnect to inject JavaScript and compromise other users’ sessions, and CVE-2026-27100 (medium) Run Parameter handling that could reveal existence of jobs/builds without permission. Upgrade to Jenkins 2.551 or LTS 2.541.2; CSP enforcement on newer Jenkins can partially mitigate XSS impact. 🎯 Target: Global/CI-CD (Jenkins) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/jenkins-vulnerability-exposes-xss-attacks/

    Post summary

    The post discloses two Jenkins core vulnerabilities, provides specific technical details, and recommends upgrading to patched versions as a mitigation.

    0000042
    174 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    Stored XSS vulnerability in node offline cause description CVE-2026-27099 Severity (CVSS): High Build information disclosure vulnerability through Run Parameter CVE-2026-27100 Severity (CVSS): Medium Jenkins Security Advisory 2026-02-18 https://www.jenkins.io/security/advisory/2026-02-18/

    Post summary

    Jenkins has announced two CVEs (CVE-2026-27099 and CVE-2026-27100) with high and medium severity, respectively, and linked to its official security advisory.

    00000353
    6.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-27099 Jenkins Stored XSS Vulnerability in Agent Offline Cause Description https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27099

    Post summary

    The text links to a vulnerability database entry for CVE-2026-27099, noting a stored XSS issue in Jenkins Agent Offline, but offers no PoC, exploit, mitigation, or active exploitation details.

    0000040
    4.0K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 HIGH severity alert: Jenkins 2.483-2.550 & LTS 2.492.1-2.541.1 face a stored XSS flaw exploitable by users with agent permissions. Patch ASAP, restrict privileges! 🔒 https://radar.offseq.com/threat/cve-2026-27099-vulnerability-in-jenkins-project-je-f2bd90c0 #OffSeq #Jenkins ... https://t.co/cjmPploerD

    Post summary

    A high‑severity stored XSS vulnerability (CVE‑2026‑27099) affecting Jenkins versions 2.483–2.550 and LTS 2.492.1–2.541.1 has been announced; users with agent permissions can exploit it. Immediate patching and privilege restriction are advised.

    0000033
    265 followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-27099 - High Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resul... https://www.thehackerwire.com/vulnerability/CVE-2026-27099/ https://t.co/zwVyHgTm33

    Post summary

    The post announces the CVE-2026-27099 vulnerability affecting certain Jenkins releases but offers no further technical detail, evidence of exploitation, or remediation guidance.

    0000043
    112 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appjenkinsjenkins---
Appjenkinsjenkins---

Explore more