CVE-2026-33002Disclosure(jenkins / jenkins)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch jenkins jenkins systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expected origin for comparison using the Host or X-Forwarded-Host HTTP request headers, making it vulnerable to DNS rebinding attacks that allow bypassing origin validation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-350

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jenkins

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 5d ago at 2 mentions (2026-03-19); latest day: 1
  • 8 total mentions across 7 days

Affected systems

Vendors
Products
jenkins

Deep dive

Activity timeline8 mentions / 7d
01122Mentions · 2026-03-18: 1Mentions · 2026-03-19: 2Mentions · 2026-03-20: 1Mentions · 2026-03-21: 1Mentions · 2026-03-26: 1Mentions · 2026-03-27: 1Mentions · 2026-04-12: 1Patch / Workaround · 2026-03-19: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-19: 2Technical Details · 2026-03-21: 1Technical Details · 2026-03-27: 1Technical Details · 2026-04-12: 103-1803-1903-2003-2103-2603-2704-12
Signal classification3 categories
Disclosure
675.0%
Patch
112.5%
General
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-181
Disclosure1
2026-03-192
Disclosure1Patch1
2026-03-201
Disclosure1
2026-03-211
Disclosure1
2026-03-261
General1
2026-03-271
Disclosure1
2026-04-121
Disclosure1
Full discourse8 posts
  • Gray Hats@the_yellow_fall
    Patch

    Jenkins patches critical flaws (CVE-2026-33001 & CVE-2026-33002) allowing remote code execution and full CI/CD pipeline compromise. Update to 2.555 now. #Jenkins #CyberSecurity #DevSecOps #CVE #InfoSec #RCE #Vulnerability #CICD #PatchAlert #TechNews https://securityonline.info/pipeline-poison-critical-jenkins-vulnerabilities-rce-cve-2026-33001/ https://t.co/rsITCpHxZA

    Post summary

    Jenkins has released patches for CVE‑2026‑33001 and CVE‑2026‑33002, which allowed remote code execution and full pipeline compromise; users are advised to upgrade to version 2.555.

    060155874
    10.7K followersView on X
  • Andre Gironda@AndreGironda
    Disclosure

    CVE-2026-33001 , CVE-2026-33002 , 2026-03-18 Before versions 2.555, LTS 2.541.3 Jenkins does not safely handle links during extraction of tar / tgz. Crafted archives can write files to arbitrary locations leading to code execution -- https://www.jenkins.io/security/advisory/2026-03-18

    Post summary

    The advisory discloses CVE-2026-33001 and CVE-2026-33002, indicating that Jenkins versions before 2.555 and LTS 2.541.3 fail to safely process symbolic links in tar/tgz archives, enabling arbitrary file writes and potential code execution.

    00050191
    3.6K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 『For archives extracted on the controller, this can result in code execution』 CVE-2026-33001、CVE-2026-33002、CVE-2026-33003、CVE-2026-33004 Jenkins Security Advisory 2026-03-18 https://www.jenkins.io/security/advisory/2026-03-18/

    Post summary

    The text announces a Jenkins security advisory for CVE‑2026‑33001 through CVE‑2026‑33004, highlighting potential code execution via archive extraction on controllers.

    00020450
    6.7K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Jenkins の複数の脆弱性が FIX:コントローラー上での RCE や CLI 実行などの恐れ https://iototsecnews.jp/2026/03/20/new-critical-jenkins-vulnerabilities-put-ci-cd-servers-at-risk-of-rce-exploits/ Jenkins プロジェクトが公開した、 コアシステムおよび LoadNinja プラグインに関する複数の深刻な脆弱性について解説する記事です。1 つ目の脆弱性 CVE-2026-33001 は、Jenkins コアにおけるアーカイブファイルの展開処理の不備に起因します。 具体的には、” .tar” 形式などのファイルを解凍する際、 シンボリックリンクを悪用する攻撃者に、本来のディレクトリ外へのファイル書き込みを許してしまいます。それにより、コンフィグ・ファイルやスクリプトの不正な配置が生じ、 最終的に Jenkins 上での任意のコード実行 (RCE) に至る恐れがあります。 また、 Jenkins CLI の脆弱性 CVE-2026-33002 は、 接続元の不十分な検証による DNS リバインディングを許すものであり、認証の回避が引き起こされます。さらに、LoadNinja プラグインでは、 API キーが平文で保存/表示されてしまうという管理上の不備が生じています。ご利用のチームは、ご注意ください。 #CVE202633001 #CVE202633002 #CVE202633003 #CVE202633004 #Jenkins #Vulnerability

    Post summary

    The article announces several newly identified Jenkins core and plugin vulnerabilities, detailing how they can lead to remote code execution and authentication bypass, without mention of PoC, exploit code, or patches.

    01000134
    481 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A DNS rebinding vulnerability in `Jenkins` WebSocket CLI origin validation (CVE-2026-33002) allows bypassing security controls. Assess your `Jenkins` deployments. #Jenkins #DNSrebinding #infosec https://www.pulsepatch.io/posts/cve-2026-33002-jenkins-dns-rebinding-vulnerability

    Post summary

    The post announces a DNS rebinding vulnerability (CVE-2026-33002) affecting Jenkins WebSocket CLI origin validation, noting it can bypass security controls and urging users to assess their deployments.

    0000050
    13 followersView on X
  • E-tomatot@ETomatot24044
    General

    >WebSocket CLIのなりすまし接続(CVE-2026-33002) >DNSリバインディング 匿名ユーザーに何らかの権限が与えられている&HTTPSではなくHTTPで運用しているという条件が必要なので、 ・ユーザー管理ができていない ・ゼロトラストを理解していない になるかな 内部ネットワークなのに、CAサーバー立てるのが面倒というのはわかるんですが、今はHashiCorp VaultやAWS Private CAなど、プライベート証明書の管理を自動化するツールは今や十分に成熟しているので、やるべきことに入れていないのが問題なのかな チェックリスト漏れだと思います

    Post summary

    The post identifies general setup shortcomings (anonymous user permissions and HTTP use) that could allow exploitation of CVE‑2026‑33002, but it provides no technical details, PoC, or patch information.

    0000064
    9 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Jenkins ❗ CVE-2026-33002 ❗ CVE-2026-33001 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-jenkins/ https://t.co/482yFHwkJX

    Post summary

    The tweet announces two new Jenkins CVEs (2026-33002 & 2026-33001) and points to a website for additional information, without sharing exploitation or mitigation details.

    0000087
    6.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33002 Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket e… https://www.cve.org/CVERecord?id=CVE-2026-33002

    Post summary

    The statement announces CVE-2026-33002, listing affected Jenkins versions and describing an origin validation flaw in the CLI WebSocket, with no mention of PoC, exploit, or mitigation.

    00000113
    56.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appjenkinsjenkins---
Appjenkinsjenkins---

Explore more