Database/Control plane, storage & DevOps
Jenkins Performance Plugin: unsafe deserialization of cached reports gives Item/Configure users RCE
Impact
The plugin does not restrict which classes may be instantiated when it deserializes cached performance reports from the build directory, so a user with Item/Configure can place crafted cached data and execute arbitrary code on the Jenkins controller. Controller code execution is full compromise of the CI identity: the credentials store, agent connections to every build node, and push access to the registries that GPU nodes pull from. Item/Configure is normally seen as a routine developer permission, not an administrative one, which is what makes this a privilege escalation rather than a nuisance. Affects Performance Plugin 1015.v09ca_52b_3370e and earlier.
Who can reach it
An authenticated user with Item/Configure permission on a job using the Performance Plugin. No user interaction required.
What to do
Update the Performance Plugin past 1015.v09ca_52b_3370e and restart the controller; the record does not name the fixed release, so check the advisory. If the plugin is unused, uninstalling it removes the exposure with the same restart. Short CI outage, no node drain.
References
Related entries
- Jenkins File Parameter Plugin: arbitrary file write on the controller via data binding leads to RCECVE-2026-84671 · Jenkins File Parameter Plugin (Stapler data binding, file write path)High
- Jenkins Entra ID plugin: a colliding Entra group display name inherits a privileged group's permissionsCVE-2026-84672 · Jenkins Microsoft Entra ID plugin (group authorization by display name)High
- KubeEdge (ConfigUpdateJob handler, updateFields): REMOTE CODE EXECUTION ON EDGE NODES via a normal Kubernetes APINCVD-2026-051-kubeedge-configupdatejob-handler · KubeEdge (ConfigUpdateJob handler, updateFields)High
- KubeEdge (NodeUpgradeJob handler, v1alpha2 API): REMOTE CODE EXECUTION ON EDGE NODES through the upgrade path. TheNCVD-2026-052-kubeedge-nodeupgradejob-handler · KubeEdge (NodeUpgradeJob handler, v1alpha2 API)High
- APC Network Management Card 4 (NMC4): An unauthenticated attacker can manipulate URL parameters to walk out of the webCVE-2024-58310 · APC Network Management Card 4 (NMC4)High
- Cisco Nexus Dashboard Fabric Controller (SSH host key validation): NDFC does not validate the SSH host keysCVE-2025-20163 · Cisco Nexus Dashboard Fabric Controller (SSH host key validation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.