Vulnerability in Jenkins Job Configuration History Plugin Allows Configuration Manipulation
CVE-2026-84666
Currently unrated
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 2 September 2026
What is CVE-2026-84666?
The Jenkins Job Configuration History Plugin, up to version 1367.vc8fa_b_15101dc, is susceptible to an issue where attackers can exploit Stapler data binding to overwrite the plugin's history recording configuration. This exploitation allows adversaries to redirect the history storage to a directory of their choice and manipulate the recording settings, potentially leading to unauthorized alterations in job configuration history.
Affected Version(s)
Jenkins Job Configuration History Plugin 0 <= 1367.vc8fa_b_15101dc