SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84658

MEDIUM · CVSS 4.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Jenkins Script Security Plugin versions up to 1412.v7737b_3405f86 are vulnerable due to improper use of the `@DataBoundConstructor` annotation, which permits unauthorized attackers to read sensitive script approval configurations by submitting specific forms. This exposure could lead to unauthorized access to script execution settings, potentially compromising the integrity of Jenkins environments. Organizations using Jenkins, particularly those with sensitive scripts or configurations, should prioritize patching this vulnerability to mitigate risks.

CVE
CVE-2026-84658
Severity
MEDIUM
CVSS
4.3
EPSS
0.19%
Jenkins

Original NVD Description

Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowing attackers able to submit certain forms to read that configuration.