GPU VulnDB

Database/Control plane, storage & DevOps

Jenkins Script Security Plugin: form submission exposes the script approval configuration to attackers

CVE-2026-84658Control plane, storage & DevOpscurated

Impact

A @DataBoundConstructor on a constructor that loads script approval configuration lets a user able to submit certain forms read that configuration. The approval list reveals which scripts and signatures the controller already trusts, which is direct reconnaissance for anyone probing the sandbox boundary on a build system. Disclosure only - no execution and no write - but it lowers the cost of a follow-on sandbox bypass on the controller that builds artifacts for the fleet. Affects Script Security Plugin 1412.v7737b_3405f86 and earlier.

Who can reach it

Authenticated low-privileged Jenkins user able to submit the affected forms over the network. No administrator rights required.

What to do

Update the Script Security Plugin past 1412.v7737b_3405f86 per the 2026-09-02 advisory (SECURITY-3986). Plugin update and controller restart; no node drain. Low urgency on its own, but bundle it with the other Script Security fix in the same advisory.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.