GPU VulnDB

Database/Control plane, storage & DevOps

Jenkins Script Security Plugin: missing permission check lets attackers disable global sandbox enforcement

CVE-2026-84659Control plane, storage & DevOpscurated

Impact

The method controlling "Force the use of the sandbox globally in the system" has no permission check, so a low-privileged authenticated user can turn it off through Stapler data binding. Disabling global sandbox enforcement removes the control that keeps pipeline Groovy from running unrestricted on the controller, widening the blast radius of any subsequent script submission. On a cluster where Jenkins builds and pushes the container images and model artifacts that run on GPU nodes, weakening that boundary is a step toward controller code execution. Affects Script Security Plugin 1412.v7737b_3405f86 and earlier.

Who can reach it

Any authenticated Jenkins user with low privileges who can reach the controller's web interface. No administrator rights and no user interaction needed.

What to do

Update the Script Security Plugin past 1412.v7737b_3405f86 per the 2026-09-02 advisory (SECURITY-3986). Plugin update plus a controller restart; no GPU node maintenance. After patching, verify the global sandbox setting is still enabled - an attacker may already have flipped it.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.