Database/Control plane, storage & DevOps
Jenkins Script Security Plugin: missing permission check lets attackers disable global sandbox enforcement
Impact
The method controlling "Force the use of the sandbox globally in the system" has no permission check, so a low-privileged authenticated user can turn it off through Stapler data binding. Disabling global sandbox enforcement removes the control that keeps pipeline Groovy from running unrestricted on the controller, widening the blast radius of any subsequent script submission. On a cluster where Jenkins builds and pushes the container images and model artifacts that run on GPU nodes, weakening that boundary is a step toward controller code execution. Affects Script Security Plugin 1412.v7737b_3405f86 and earlier.
Who can reach it
Any authenticated Jenkins user with low privileges who can reach the controller's web interface. No administrator rights and no user interaction needed.
What to do
Update the Script Security Plugin past 1412.v7737b_3405f86 per the 2026-09-02 advisory (SECURITY-3986). Plugin update plus a controller restart; no GPU node maintenance. After patching, verify the global sandbox setting is still enabled - an attacker may already have flipped it.
References
Related entries
- Jenkins LDAP plugin: Stapler data binding lets a low-privileged user make the controller connect to any URLCVE-2026-84662 · Jenkins LDAP plugin (Stapler data binding, attacker-specified connection URL)Medium
- Jenkins Parameterized Remote Trigger plugin: remote trigger tokens stored unencrypted in job config.xmlCVE-2026-84676 · Jenkins Parameterized Remote Trigger plugin (tokens stored unencrypted in job config.xml)Medium
- GitLab CE/EE: developer-role user can modify package registry metadata without maintainer rightsCVE-2026-8667 · GitLab CE/EE (package registry metadata authorization)Medium
- Infineon cryptographic library (ECDSA) in security microcontrollers: Electromagnetic side channel in Infineon's ECDSACVE-2024-45678 · Infineon cryptographic library (ECDSA) in security microcontrollersMedium
- Slurm (slurmdbd accounting, Coordinator role): A Coordinator - the delegated role a site gives a team lead over theirCVE-2025-43904 · Slurm (slurmdbd accounting, Coordinator role)Medium
- HTCondor (condor_schedd / Access Point): A user plants a specially crafted job that lies dormant, then runs as aCVE-2025-66433 · HTCondor (condor_schedd / Access Point)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.