GPU VulnDB

Database/Control plane, storage & DevOps

Jenkins Stapler: form data binding instantiates configuration types the target field never expected

CVE-2026-84647Control plane, storage & DevOpscurated

Impact

Stapler does not restrict form data binding to objects compatible with the declared field type, so a user with only Overall/Read can cause instantiation of configuration-related types that were never intended for that field. The practical consequence depends on which type is chosen, but the entry point requires only read-level access to the controller, which is the permission level most organisations hand out freely to everyone who looks at build results. On a Jenkins that drives GPU cluster deployments, the controller holds cluster credentials, so any foothold that escalates from read-only towards configuration handling is worth patching promptly. Affects Stapler 2107.v8dfcb_e8ed317 and earlier (except 2088.2093.vd7c3e58008a_6) as shipped in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier.

Who can reach it

Any authenticated user with Overall/Read on the Jenkins controller. No user interaction required.

What to do

Upgrade Jenkins so it ships a fixed Stapler build, then restart the controller - Stapler is a core library, so there is no plugin-only fix. The record does not name the fixed version; read the advisory. Cost is a short controller outage, no impact on GPU nodes.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.