SAML Identity Provider Metadata Overwriting in Jenkins Plugin
CVE-2026-84668

8.8HIGH

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
2 September 2026

What is CVE-2026-84668?

The Jenkins SAML Plugin prior to version 4.619 allows an attacker to overwrite the SAML identity provider metadata file through a flaw in Stapler data binding. This vulnerability enables an attacker to replace the legitimate metadata with malicious content, facilitating unauthorized authentication as any user. It is crucial for organizations using this plugin to be aware of the implications of this vulnerability and to update to a patched version to mitigate risks.

Affected Version(s)

Jenkins SAML Plugin 0 <= 4.618.v441a_27fa_46d2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.