GPU VulnDB

Database/Control plane, storage & DevOps

Jenkins Performance Plugin: unsafe deserialization of cached reports gives Item/Configure users RCE

CVE-2026-84670Control plane, storage & DevOpscurated

Impact

The plugin does not restrict which classes may be instantiated when it deserializes cached performance reports from the build directory, so a user with Item/Configure can place crafted cached data and execute arbitrary code on the Jenkins controller. Controller code execution is full compromise of the CI identity: the credentials store, agent connections to every build node, and push access to the registries that GPU nodes pull from. Item/Configure is normally seen as a routine developer permission, not an administrative one, which is what makes this a privilege escalation rather than a nuisance. Affects Performance Plugin 1015.v09ca_52b_3370e and earlier.

Who can reach it

An authenticated user with Item/Configure permission on a job using the Performance Plugin. No user interaction required.

What to do

Update the Performance Plugin past 1015.v09ca_52b_3370e and restart the controller; the record does not name the fixed release, so check the advisory. If the plugin is unused, uninstalling it removes the exposure with the same restart. Short CI outage, no node drain.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.