PT-2026-84794 · Jenkins · Jenkins File Parameter Plugin

CVE-2026-84671

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Jenkins File Parameter Plugin 425.v3fa 801681b 5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system through Stapler data binding, which can lead to remote code execution.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84671

Affected Products

Jenkins File Parameter Plugin