CVE-2026-70448: Vulnerability in Jenkins Project Jenkins Ivy Report Plugin
Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files.
AI Analysis
Technical Summary
The Jenkins Ivy Report Plugin up to version 1.2 does not properly configure its XML parser to mitigate XML external entity (XXE) attacks during the processing of Ivy report files. This vulnerability arises because the XML parser accepts external entities, which can be exploited to read local files, perform server-side request forgery, or cause denial of service. The vulnerability is documented as CVE-2026-70448. No CVSS score or vendor advisory with patch information is currently available.
Potential Impact
An attacker who can supply or influence Ivy report files processed by the plugin may exploit the XXE vulnerability to access sensitive information, cause denial of service, or perform other unauthorized actions depending on the XML parser's behavior. However, no known exploits have been reported in the wild to date.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid processing untrusted Ivy report files with the affected plugin versions or apply XML parser hardening if possible.
CVE-2026-70448: Vulnerability in Jenkins Project Jenkins Ivy Report Plugin
Description
Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files.
CVSS v3.1
Score 7.1high
Affected software
Jenkins Project
Jenkins Ivy Report Plugin
pkg:github/jenkinsci/ivy-report-pluginRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Jenkins Ivy Report Plugin up to version 1.2 does not properly configure its XML parser to mitigate XML external entity (XXE) attacks during the processing of Ivy report files. This vulnerability arises because the XML parser accepts external entities, which can be exploited to read local files, perform server-side request forgery, or cause denial of service. The vulnerability is documented as CVE-2026-70448. No CVSS score or vendor advisory with patch information is currently available.
Potential Impact
An attacker who can supply or influence Ivy report files processed by the plugin may exploit the XXE vulnerability to access sensitive information, cause denial of service, or perform other unauthorized actions depending on the XML parser's behavior. However, no known exploits have been reported in the wild to date.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid processing untrusted Ivy report files with the affected plugin versions or apply XML parser hardening if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- jenkins
- Date Reserved
- 2026-08-04T14:13:20.603Z
- State
- PUBLISHED
Threat ID: 6a737986bf8831d5393d6f26
Added to database: 08/05/2026, 17:57:26 UTC
Last enriched: 08/05/2026, 18:18:59 UTC
Last updated: 09/18/2026, 22:01:37 UTC
Views: 66
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.