CVE-2026-84659 PUBLISHED

Assigner: jenkins
Reserved: 01.09.2026 Published: 02.09.2026 Updated: 02.09.2026

Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, allowing attackers to disable it through Stapler data binding.

Product Status

Vendor Jenkins Project
Product Jenkins Script Security Plugin
Versions Default: unaffected
  • affected from 0 to 1412.v7737b_3405f86 (incl.)

References