CVE-2026-84659
Awaiting Analysis Awaiting Analysis - Queue

Jenkins Script Security Plugin Permission Bypass via Stapler Data Binding

Vulnerability report for CVE-2026-84659, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: Jenkins Project

Description

Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, allowing attackers to disable it through Stapler data binding.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-15
AI Q&A
2026-09-02
EPSS Evaluated
2026-09-14
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jenkinsci script_security_plugin to 1412.v7737b_3405f86 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Jenkins Script Security Plugin allows attackers to disable the global sandbox setting through Stapler data binding without proper permission checks. The plugin versions 1412.v7737b_3405f86 and earlier are affected.

Detection Guidance

This vulnerability can be detected by checking if the Jenkins Script Security Plugin version is 1412.v7737b_3405f86 or earlier. Review the plugin configuration to ensure the 'Force the use of the sandbox globally in the system' setting is enabled and cannot be disabled by unauthorized users.

Impact Analysis

Attackers could exploit this to bypass security controls, potentially executing malicious scripts on the Jenkins system. This may lead to unauthorized code execution, data breaches, or system compromise depending on the Jenkins environment.

Compliance Impact

This vulnerability allows attackers to disable the sandbox globally in Jenkins, potentially enabling execution of malicious scripts. This could lead to unauthorized data access or modification, which may violate GDPR (data protection) or HIPAA (health data security) compliance by exposing sensitive information.

Mitigation Strategies

Update Jenkins Script Security Plugin to version 1412.v7737b_3405f86 or later to ensure proper permission checks are enforced.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84659. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart