SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84664

MEDIUM · CVSS 5.4 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Jenkins GitLab Plugin versions 1.9.16 and earlier are vulnerable to a configuration overwrite that enables attackers to manipulate the global GitLab connection settings via Stapler data binding. This flaw allows unauthorized connections to arbitrary URLs using existing GitLab API tokens, potentially compromising sensitive data and access. Organizations using these versions of the Jenkins GitLab Plugin should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-84664
Severity
MEDIUM
CVSS
5.4
EPSS
0.10%
Jenkins GitLab

Original NVD Description

Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowing attackers to connect to an attacker-specified URL using GitLab API tokens already configured by administrators.