SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84676

MEDIUM · CVSS 4.3 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Parameterized Remote Trigger Plugin for Jenkins versions 3.2.2 and earlier is vulnerable due to the storage of tokens in plaintext within job config.xml files, allowing users with Item/Extended Read permissions or file system access to view sensitive information. This exposure could lead to unauthorized access or manipulation of Jenkins jobs. Organizations using affected versions of Jenkins should prioritize remediation to protect against potential credential leakage and unauthorized actions within their CI/CD pipelines.

CVE
CVE-2026-84676
Severity
MEDIUM
CVSS
4.3
EPSS
0.12%
Jenkins

Original NVD Description

Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.