Vulnerability in Jenkins Script Security Plugin Disables Sandbox Protection
CVE-2026-84659
Currently unrated
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 2 September 2026
What is CVE-2026-84659?
The Jenkins Script Security Plugin prior to version 1412.v7737b_3405f86 lacks adequate permission checks in the method that manages the global sandbox setting. This flaw enables unauthorized attackers to disable the sandbox protection capability, potentially allowing them to execute untrusted scripts without proper security restrictions. This vulnerability poses significant risks to the integrity and security of Jenkins installations.
Affected Version(s)
Jenkins Script Security Plugin 0 <= 1412.v7737b_3405f86