Path Traversal Issue in Jenkins Allure Plugin by Jenkins
CVE-2026-84669
8.8HIGH
What is CVE-2026-84669?
A path traversal vulnerability exists in the Allure Plugin for Jenkins, specifically versions 2.35.2 and earlier. This vulnerability allows attackers with Item/Read permissions on specific jobs, which publish Allure report results, to read arbitrary files located on the Jenkins controller's file system. The exposed files may contain sensitive information, thereby posing a significant risk to the integrity and confidentiality of the Jenkins environment.
Affected Version(s)
Jenkins Allure Plugin 0 <= 2.35.2