CVE-2026-84669
Received Received - Intake

Path Traversal in Jenkins Allure Plugin

Vulnerability report for CVE-2026-84669, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: Jenkins Project

Description

A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permission on jobs that publish Allure report results to read arbitrary files on the Jenkins controller's file system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jenkinsci allure_plugin to 2.35.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in Jenkins Allure Plugin versions 2.35.2 and earlier. It allows attackers with Item/Read permission to access arbitrary files on the Jenkins controller's file system by exploiting how the plugin handles report paths.

Impact Analysis

Attackers could read sensitive files on the Jenkins controller, potentially exposing confidential data like credentials, configuration files, or other restricted information. This could lead to further attacks or data breaches.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating compliance requirements under GDPR, HIPAA, or other regulations. Organizations may face legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Update Jenkins Allure Plugin to a version later than 2.35.2. If an update is not available, consider disabling the plugin or restricting Item/Read permissions for affected jobs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84669. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart