Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Elie Metahri

Researcher fromAirbus Protect Offensive Security Team
#20924of 56,330
13.3Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-26073
9.0
2026-03-18
Jenkins · Jenkins · CVE-2026-33001
**Name of the Vulnerable Software and Affected Versions** Jenkins versions prior to 2.555 Jenkins LTS versions prior to 2.541.3 **Description** Unsafe handling of symbolic links during the extraction of .tar and .tar.gz archives allows attackers with Item/Configure permission, or those who can control agent processes, to write files to arbitrary locations on the filesystem. This action is restricted only by the file system access permissions of the user running Jenkins. Such a flaw could enable the deployment of malicious scripts or plugins on the Jenkins controller, potentially leading to unauthorized code execution. **Recommendations** Update Jenkins to version 2.555 or later. Update Jenkins LTS to version 2.541.3 or later.
PT-2026-26076
4.3
2026-03-18
Jenkins · Jenkins Loadninja Plugin · CVE-2026-33004
**Name of the Vulnerable Software and Affected Versions** Jenkins LoadNinja Plugin versions 2.1 and earlier **Description** The Jenkins LoadNinja Plugin does not properly mask LoadNinja API keys as they are displayed on the job configuration form. This could allow attackers to observe and capture these keys. **Recommendations** Update to a newer version of the Jenkins LoadNinja Plugin that addresses this issue.