How to audit a Jenkins controller in 2026
API readable with no login?
Deeper than a manual audit or a tool. At the scale AI agents attack.
The audit starts after signup. $49 for one month. Your report stays in your account.
- Version and plugins
- Known CVEs
- Anonymous access
- Script console
01 / 08·running
Public surface
Other hosts and open ports
Signals
- Version and pluginsThe controller release, and the plugin list when Jenkins will show it.
- Known CVEsPublished holes in that core and in the plugins we could read.
- Anonymous accessThe API, the people directory, and the CLI with no login.
- Script consoleThe script console and Manage Jenkins reachable from the internet.
How the Jenkins audit runs
What else is on this domain
Other hostnames on the same domain, then the ports those servers leave open, before anything Jenkins-specific.
Subdomains
Staging, old admin hosts, and the other names on your domain.
Live hosts
Which of those names actually answer.
Open ports
What is listening, including the version when the server says it.
On your Jenkins
Jenkins version and plugins, anonymous API read, the people directory, and the script console.
Version and plugins
The controller release, and the plugin list when Jenkins will show it.
Known CVEs
Published holes in that core and in the plugins we could read.
Anonymous access
The API, the people directory, and the CLI with no login.
Script console
The script console and Manage Jenkins reachable from the internet.
A report you can act on
Each issue names the host, shows the evidence, and says what to fix. Anything we could not confirm stays marked that way.
Evidence
The URL or file that proved it.
CVE ids
Only when we saw the version the advisory is about.
Account
The report opens after the $49 month is paid.
Questions about a Jenkins audit
What the run covers, and when the report opens in the account.
Contact usAudit Jenkins from the outside.
Deeper than a manual audit or a tool. At the scale AI agents attack.