OS Command Injection Vulnerability in Jenkins TICS Plugin
CVE-2026-84675

7.4HIGH

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
2 September 2026

What is CVE-2026-84675?

The Jenkins TICS Plugin is susceptible to an OS command injection vulnerability that occurs when a malicious user is able to manipulate build environment variable values. This can enable the execution of arbitrary commands on the agent responsible for running the build, potentially compromising the integrity and security of the Jenkins environment. It is essential for administrators to review the affected plugin versions and implement the necessary updates to safeguard against this type of attack.

Affected Version(s)

Jenkins TICS Plugin 0 <= 2025.1.1

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.