Skip to finding
important · Automation

Delegated Jenkins configuration access can reach controller-side script execution.

Affects

Jenkins, a Java-based automation and continuous-integration controller commonly entrusted with build credentials and artifact production.

A crafted config.xml can deserialize a nested PersistenceRoot object, expose its Stapler routes and reach the improperly protected Script Console in the controller process.

Detail and 1 source

Jenkins published fixed releases, and no public exploit code was located by the cutoff.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 4, 2026