CVE-2026-84659
Received Received - Intake

Jenkins Script Security Plugin Permission Bypass via Stapler Data Binding

Vulnerability report for CVE-2026-84659, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: Jenkins Project

Description

Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, allowing attackers to disable it through Stapler data binding.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jenkinsci script_security_plugin to 1412.v7737b_3405f86 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Jenkins Script Security Plugin allows attackers to disable the global sandbox setting through Stapler data binding without proper permission checks. The plugin versions 1412.v7737b_3405f86 and earlier are affected.

Impact Analysis

Attackers could exploit this to bypass security controls, potentially executing malicious scripts on the Jenkins system. This may lead to unauthorized code execution, data breaches, or system compromise depending on the Jenkins environment.

Mitigation Strategies

Update Jenkins Script Security Plugin to version 1412.v7737b_3405f86 or later to ensure proper permission checks are enforced.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84659. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart