Arbitrary Code Execution Vulnerability in Jenkins Performance Plugin by Jenkins
CVE-2026-84670
8.8HIGH
What is CVE-2026-84670?
The Jenkins Performance Plugin versions up to 1015.v09ca_52b_3370e are vulnerable to an arbitrary code execution risk due to improper restrictions on class instantiation during the deserialization of cached performance reports. Attackers possessing Item/Configure permissions can exploit this flaw to execute unauthorized code on the Jenkins controller, potentially compromising the entire server.
Affected Version(s)
Jenkins Performance Plugin 0 <= 1015.v09ca_52b_3370e