Configuration Overwrite Risk in Jenkins GitLab Plugin by Jenkins
CVE-2026-84664
Currently unrated
What is CVE-2026-84664?
The Jenkins GitLab Plugin versions 1.9.16 and earlier are susceptible to a vulnerability that allows attackers to overwrite the global GitLab connection configuration. This could enable unauthorized access through the use of valid GitLab API tokens that were previously configured by administrators. Attackers can leverage this flaw to connect to malicious URLs, resulting in potential data exposure and further compromising system integrity. For more details, visit the Jenkins Security Advisory.
Affected Version(s)
Jenkins GitLab Plugin 0 <= 1.9.16