Arbitrary File Write Vulnerability in Jenkins File Parameter Plugin
CVE-2026-84671

8.8HIGH

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
2 September 2026

What is CVE-2026-84671?

The Jenkins File Parameter Plugin, specifically version 425.v3fa_801681b_5e and earlier, contains a vulnerability that permits attackers to write files to arbitrary locations on the Jenkins controller file system. This weakness arises from improper data binding through the Stapler framework, potentially leading to unauthorized remote code execution. Organizations using this plugin should prioritize reviewing their systems and applying necessary updates to mitigate possible security risks.

Affected Version(s)

Jenkins File Parameter Plugin 0 <= 425.v3fa_801681b_5e

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.