SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84671

HIGH · CVSS 8.8 EPSS 0.57% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Jenkins File Parameter Plugin versions up to 425.v3fa_801681b_5e are vulnerable to a high-severity flaw that permits unauthorized file writing to arbitrary locations on the Jenkins controller file system via Stapler data binding. This vulnerability could lead to remote code execution, posing significant risks to the integrity and security of Jenkins environments. Organizations using affected versions of Jenkins should prioritize patching this vulnerability to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84671
Severity
HIGH
CVSS
8.8
EPSS
0.57%
Jenkins

Original NVD Description

Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system through Stapler data binding, which can lead to remote code execution.