PT-2026-84794 · Jenkins · Jenkins File Parameter Plugin
CVE-2026-84671
·
Published
2026-09-02
·
Updated
2026-09-02
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Jenkins File Parameter Plugin 425.v3fa 801681b 5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system through Stapler data binding, which can lead to remote code execution.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins File Parameter Plugin