Intel

AIKIDO-2026-784914

jenkins-multijob-plugin is vulnerable to Remote Code Execution (RCE)

Remote Code Execution (RCE)CVE-2026-70431 Published 3 days ago

84

High Risk

This Affects:

JAVAjenkins-multijob-plugin
0.0.1 - 669
Fixed in 677
Are you affected? Scan for Free

TL;DR

Groovy scripting features in Multijob do not integrate with Script Security Plugin sandboxing. An attacker with Item/Create or Item/Configure permission can run arbitrary code in the Jenkins controller JVM. The fix runs those scripts through Script Security Plugin sandboxing.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and users with Item/Create or Item/Configure permission can edit Multijob Groovy scripts.

Background info

jenkins-multijob-plugin is vulnerable to Remote Code Execution (RCE) in versions 0.0.1 - 669.

How to fix this

Upgrade the org.jenkins-ci.plugins:jenkins-multijob-plugin library to the patch version.