CVE-2026-84675
Received Received - Intake

Command Injection in Jenkins TICS Plugin

Vulnerability report for CVE-2026-84675, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: Jenkins Project

Description

OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jenkinsci tics_plugin to 2025.1.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an OS command injection flaw in the Jenkins TICS Plugin version 2025.1.1 and earlier. It allows attackers who can control build environment variable values to execute arbitrary commands on the agent running the build.

Detection Guidance

To detect this vulnerability, inspect Jenkins build logs for suspicious commands executed via the TICS Plugin. Check for unusual environment variable values or build steps that may indicate command injection. Review plugin configurations for exposed build parameters.

Impact Analysis

If you use the affected Jenkins TICS Plugin, attackers could exploit this to run unauthorized commands on your build agents. This could lead to data breaches, system compromise, or disruption of build processes.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized command execution on build agents. If exploited, it may lead to data breaches, unauthorized access to sensitive information, or manipulation of build environments, which could violate data protection requirements under these regulations.

Mitigation Strategies

Update Jenkins TICS Plugin to a version later than 2025.1.1 to remove the vulnerability. If updating is not possible, disable the plugin or restrict access to build environment variable controls.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84675. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart