CVE-2026-27100Patch(jenkins / jenkins)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch jenkins jenkins systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values that refer to builds the user submitting the build does not have access to, allowing attackers with Item/Build and Item/Configure permission to obtain information about the existence of jobs, the existence of builds, and if a specified build exists, its display name.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jenkins

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 2 mentions (2026-02-18); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
jenkins

Deep dive

Activity timeline7 mentions / 4d
01122Mentions · 2026-02-18: 2Mentions · 2026-02-19: 2Mentions · 2026-02-20: 2Mentions · 2026-02-27: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-20: 2Patch / Workaround · 2026-02-27: 1Technical Details · 2026-02-18: 2Technical Details · 2026-02-19: 2Technical Details · 2026-02-20: 2Technical Details · 2026-02-27: 102-1802-1902-2002-27
Signal classification2 categories
Patch
457.1%
Disclosure
342.9%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-182
Disclosure2
2026-02-192
Disclosure1Patch1
2026-02-202
Patch2
2026-02-271
Patch1
Full discourse7 posts
  • Open Source Security mailing list@oss_security
    Patch

    Multiple vulnerabilities in Jenkins https://www.openwall.com/lists/oss-security/2026/02/18/4 Fixed in 2.551 and LTS 2.541.2 CVE-2026-27099 "Mark temporarily offline" stored XSS exploitable by attackers with Agent/Configure or Agent/Disconnect permission CVE-2026-27100 Run Parameter information disclosure

    Post summary

    An advisory reports two Jenkins vulnerabilities – a stored XSS (CVE‑2026‑27099) and a run‑parameter info disclosure (CVE‑2026‑27100) – and notes that they are fixed in Jenkins 2.551 and 2.541.2.

    00042340
    4.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27100 Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values that refer to builds the user submitting the build does not have access to, allowing a… https://www.cve.org/CVERecord?id=CVE-2026-27100

    Post summary

    The CVE details a Jenkins vulnerability where users can reference builds they lack access to via Run Parameter values, potentially enabling unauthorized actions.

    00011110
    56.4K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Jenkins の脆弱性 CVE-2026-27099/27100 が FIX:ビルド環境が XSS 攻撃の標的に https://iototsecnews.jp/2026/02/20/critical-jenkins-flaw-exposes-build-environments-to-xss-attacks/ CI/CD パイプラインの心臓部である Jenkins において、管理者権限の奪取や内部情報の偵察につながる 2 件の脆弱性が修正されました。最も危険なのは、エージェント・ノードのオフライン原因を処理する際にトリガーされる脆弱性 CVE-2026-27099 です。Jenkins には、ノードを切り離す際に管理者が理由をメモする機能がありますが、この入力内容が適切に無害化されず、そのまま HTML として実行されてしまう設計になっていました。もう 1 つの脆弱性 CVE-2026-27100 は、本来は見ることができないはずの “ビルドの存在や名称” を、パラメータを通じて外部から推測/特定できてしまうという情報漏洩の問題です。これらの不備は、ソフトウェア開発の自動化プロセスそのものを攻撃の拠点に変えてしまうリスクを秘めています。ご利用のチームは、ご注意ください。 #CVE202627099 #CVE202627100 #Jenkins #Vulnerability

    Post summary

    The article announces that Jenkins CVE‑2026‑27099 and CVE‑2026‑27100, involving XSS and information disclosure, have been patched, detailing the technical nature of the flaws.

    01000154
    485 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27100 Jenkins Information Disclosure Vulnerability in Run Parameter Configuration https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27100

    Post summary

    The text announces CVE‑2026‑27100, an information‑disclosure flaw in Jenkins’ run‑parameter configuration, and provides a link to a vulnerability details page.

    0001027
    4.0K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Jenkins Core hit by critical stored XSS flaw CVE-2026-27099 exposing build environments, plus CVE-2026-27100, disclosed by the European Commission under the Jenkins Bug Bounty. Admins should plan fixes. #XSS https://threatcluster.io/cluster/critical-jenkins-vulnerability-exposes-build-environments-to-23a07ce9

    Post summary

    Jenkins Core is affected by a critical stored XSS vulnerability (CVE‑2026‑27099) that exposes build environments; admins are urged to plan and apply the necessary fixes.

    0000048
    71 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Critical Jenkins Core Bugs: Stored XSS + Build Info Leak Fixed in 2.551 / LTS 2.541.2 Jenkins disclosed two core flaws: CVE-2026-27099 (high) stored XSS via unescaped “node offline cause description” allowing users with Agent/Configure or Agent/Disconnect to inject JavaScript and compromise other users’ sessions, and CVE-2026-27100 (medium) Run Parameter handling that could reveal existence of jobs/builds without permission. Upgrade to Jenkins 2.551 or LTS 2.541.2; CSP enforcement on newer Jenkins can partially mitigate XSS impact. 🎯 Target: Global/CI-CD (Jenkins) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/jenkins-vulnerability-exposes-xss-attacks/

    Post summary

    Jenkins disclosed two core vulnerabilities (stored XSS in CVE-2026-27099 and build info leak in CVE-2026-27100). Users are advised to upgrade to Jenkins 2.551 or LTS 2.541.2, or apply CSP mitigation, to patch the issues.

    0000042
    174 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    Stored XSS vulnerability in node offline cause description CVE-2026-27099 Severity (CVSS): High Build information disclosure vulnerability through Run Parameter CVE-2026-27100 Severity (CVSS): Medium Jenkins Security Advisory 2026-02-18 https://www.jenkins.io/security/advisory/2026-02-18/

    Post summary

    The text announces two new Jenkins CVEs—CVE-2026-27099 (stored XSS) and CVE-2026-27100 (build info disclosure)—providing severity scores and a link to the official advisory.

    00000353
    6.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appjenkinsjenkins---
Appjenkinsjenkins---

Explore more