SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84659

MEDIUM · CVSS 4.3 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Jenkins Script Security Plugin versions up to 1412.v7737b_3405f86 are vulnerable due to a lack of permission checks in the method that manages the global sandbox setting, which could allow unauthorized users to disable sandbox protections. This vulnerability could lead to the execution of untrusted scripts, potentially compromising the integrity of the Jenkins environment. Organizations using affected versions of Jenkins should prioritize remediation to safeguard against potential exploitation.

CVE
CVE-2026-84659
Severity
MEDIUM
CVSS
4.3
EPSS
0.17%
Jenkins

Original NVD Description

Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, allowing attackers to disable it through Stapler data binding.