CVE-2026-84659

Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, allowing attackers to disable it through Stapler data binding.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 16:17

Updated : 2026-09-03 17:13


NVD link : CVE-2026-84659

Mitre link : CVE-2026-84659

CVE.ORG link : CVE-2026-84659


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization