SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84663

MEDIUM · CVSS 5.4 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Jenkins Pipeline: Groovy Libraries Plugin versions 798.v5cc688825312 and earlier are vulnerable to a cross-site request forgery (CSRF) attack that enables unauthorized deletion of shared library caches. This could disrupt the functionality of Jenkins pipelines, potentially leading to service outages or loss of critical library resources. Organizations using affected versions of this plugin should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-84663
Severity
MEDIUM
CVSS
5.4
EPSS
0.11%
Jenkins

Original NVD Description

A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 798.v5cc688825312 and earlier allows attackers to delete shared library caches.