Configuration Overwrite Risk in Jenkins GitLab Plugin by Jenkins
CVE-2026-84664

Currently unrated

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
2 September 2026

What is CVE-2026-84664?

The Jenkins GitLab Plugin versions 1.9.16 and earlier are susceptible to a vulnerability that allows attackers to overwrite the global GitLab connection configuration. This could enable unauthorized access through the use of valid GitLab API tokens that were previously configured by administrators. Attackers can leverage this flaw to connect to malicious URLs, resulting in potential data exposure and further compromising system integrity. For more details, visit the Jenkins Security Advisory.

Affected Version(s)

Jenkins GitLab Plugin 0 <= 1.9.16

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.