SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84675

HIGH · CVSS 7.4 EPSS 1.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Jenkins TICS Plugin versions up to 2025.1.1 are vulnerable to an OS command injection flaw that enables attackers with control over build environment variables to execute arbitrary commands on the build agent. This vulnerability poses a significant risk, as it can lead to unauthorized access and manipulation of the system. Organizations using affected versions of Jenkins should prioritize patching this vulnerability to safeguard their build environments.

CVE
CVE-2026-84675
Severity
HIGH
CVSS
7.4
EPSS
1.23%
Jenkins

Original NVD Description

OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build.