PT-2026-84791 · Jenkins · Saml Plugin
CVE-2026-84668
·
Published
2026-09-02
·
Updated
2026-09-03
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jenkins SAML Plugin versions prior to 4.618.v441a 27fa 46d2
Description
Improper access control allows authenticated users to overwrite the SAML identity provider metadata file via Stapler data binding. This enables an attacker to replace the metadata with controlled content and authenticate as any user, effectively taking over the SAML authentication flows.
Recommendations
Update Jenkins SAML Plugin to a version later than 4.618.v441a 27fa 46d2.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Saml Plugin