Database/Control plane, storage & DevOps
Jenkins SAML Plugin: IdP metadata file overwritable via data binding, allowing login as any user
Impact
The SAML identity provider metadata file can be overwritten through Stapler data binding, so an attacker replaces the trusted IdP with one they control and then authenticates as any user, including administrators. This defeats the single sign-on boundary itself rather than a single account: MFA, IdP conditional access and central deprovisioning all stop applying to this Jenkins. For a GPU operator that means the controller holding kubeconfigs, registry push credentials and node keys can be entered by anyone who reaches the flaw, regardless of what the corporate IdP says. Affects SAML Plugin 4.618.v441a_27fa_46d2 and earlier.
Who can reach it
An authenticated Jenkins user with low privileges - the vector is data binding on the controller, not the SAML protocol flow. No user interaction required.
What to do
Update the Jenkins SAML Plugin past 4.618.v441a_27fa_46d2 and restart the controller; the record does not name the fixed release, so check the advisory. After patching, verify the on-disk IdP metadata matches what your identity provider publishes - if it was already replaced, upgrading alone does not undo that. Short CI outage; no GPU node impact.
References
Related entries
- Jenkins Allure Plugin: path traversal lets Item/Read users read arbitrary controller filesCVE-2026-84669 · Jenkins Allure Plugin (report path handling)High
- Jenkins Performance Plugin: unsafe deserialization of cached reports gives Item/Configure users RCECVE-2026-84670 · Jenkins Performance Plugin (cached performance report deserialization)High
- Jenkins File Parameter Plugin: arbitrary file write on the controller via data binding leads to RCECVE-2026-84671 · Jenkins File Parameter Plugin (Stapler data binding, file write path)High
- Jenkins Entra ID plugin: a colliding Entra group display name inherits a privileged group's permissionsCVE-2026-84672 · Jenkins Microsoft Entra ID plugin (group authorization by display name)High
- KubeEdge (ConfigUpdateJob handler, updateFields): REMOTE CODE EXECUTION ON EDGE NODES via a normal Kubernetes APINCVD-2026-051-kubeedge-configupdatejob-handler · KubeEdge (ConfigUpdateJob handler, updateFields)High
- KubeEdge (NodeUpgradeJob handler, v1alpha2 API): REMOTE CODE EXECUTION ON EDGE NODES through the upgrade path. TheNCVD-2026-052-kubeedge-nodeupgradejob-handler · KubeEdge (NodeUpgradeJob handler, v1alpha2 API)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.