GPU VulnDB

Database/Control plane, storage & DevOps

Jenkins SAML Plugin: IdP metadata file overwritable via data binding, allowing login as any user

CVE-2026-84668Control plane, storage & DevOpscurated

Impact

The SAML identity provider metadata file can be overwritten through Stapler data binding, so an attacker replaces the trusted IdP with one they control and then authenticates as any user, including administrators. This defeats the single sign-on boundary itself rather than a single account: MFA, IdP conditional access and central deprovisioning all stop applying to this Jenkins. For a GPU operator that means the controller holding kubeconfigs, registry push credentials and node keys can be entered by anyone who reaches the flaw, regardless of what the corporate IdP says. Affects SAML Plugin 4.618.v441a_27fa_46d2 and earlier.

Who can reach it

An authenticated Jenkins user with low privileges - the vector is data binding on the controller, not the SAML protocol flow. No user interaction required.

What to do

Update the Jenkins SAML Plugin past 4.618.v441a_27fa_46d2 and restart the controller; the record does not name the fixed release, so check the advisory. After patching, verify the on-disk IdP metadata matches what your identity provider publishes - if it was already replaced, upgrading alone does not undo that. Short CI outage; no GPU node impact.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.