CVE-2026-84666
Received Received - Intake

Jenkins Job Configuration History Plugin Path Traversal Vulnerability

Vulnerability report for CVE-2026-84666, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: Jenkins Project

Description

Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration through Stapler data binding, allowing attackers to redirect history storage to an attacker-specified directory and modify history recording settings.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jenkinsci job_configuration_history_plugin 1367.vc8fa_b_15101dc

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Jenkins Job Configuration History Plugin versions 1367.vc8fa_b_15101dc and earlier are vulnerable to improper input validation. Attackers can exploit Stapler data binding to overwrite the plugin's history recording configuration. This allows them to redirect history storage to a directory of their choice and modify settings related to history recording.

Impact Analysis

This vulnerability could allow attackers to manipulate or delete configuration history records stored by the plugin. If exploited, it may lead to loss of audit trails, making it difficult to track changes or identify unauthorized modifications in Jenkins job configurations.

Compliance Impact

This vulnerability could potentially affect compliance with GDPR or HIPAA by allowing unauthorized modification of configuration history, which may lead to undetected unauthorized changes or data tampering. If history recording is redirected or altered, it could obscure evidence of compliance violations or data breaches.

Mitigation Strategies

Update Jenkins Job Configuration History Plugin to a version later than 1367.vc8fa_b_15101dc to remove the vulnerability. Disable or restrict access to the plugin's configuration interface until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84666. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart