SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84666

MEDIUM · CVSS 5.4 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Jenkins Job Configuration History Plugin versions up to 1367.vc8fa_b_15101dc are vulnerable to an attack that allows unauthorized modification of the history recording configuration via Stapler data binding. This can enable attackers to redirect the storage of job history to a location of their choosing, potentially compromising sensitive configuration data. Organizations using this plugin should prioritize remediation to prevent unauthorized access and manipulation of job history records.

CVE
CVE-2026-84666
Severity
MEDIUM
CVSS
5.4
EPSS
0.10%
Jenkins

Original NVD Description

Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration through Stapler data binding, allowing attackers to redirect history storage to an attacker-specified directory and modify history recording settings.