Vulnerability in Jenkins Script Security Plugin Disables Sandbox Protection
CVE-2026-84659

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
2 September 2026

What is CVE-2026-84659?

The Jenkins Script Security Plugin prior to version 1412.v7737b_3405f86 lacks adequate permission checks in the method that manages the global sandbox setting. This flaw enables unauthorized attackers to disable the sandbox protection capability, potentially allowing them to execute untrusted scripts without proper security restrictions. This vulnerability poses significant risks to the integrity and security of Jenkins installations.

Affected Version(s)

Jenkins Script Security Plugin 0 <= 1412.v7737b_3405f86

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.