PT-2026-84782 · Jenkins · Jenkins Script Security Plugin

CVE-2026-84659

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Jenkins Script Security Plugin 1412.v7737b 3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, allowing attackers to disable it through Stapler data binding.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84659

Affected Products

Jenkins Script Security Plugin