GPU VulnDB

Database/Control plane, storage & DevOps

Jenkins File Parameter Plugin: arbitrary file write on the controller via data binding leads to RCE

CVE-2026-84671Control plane, storage & DevOpscurated

Impact

The plugin allows writing files to arbitrary locations on the Jenkins controller filesystem through Stapler data binding, which the advisory states can lead to remote code execution. Arbitrary write on a controller is a short path to persistence - init scripts, plugin directories, cron - and from there to the credentials that let the controller deploy onto the GPU fleet. Anything the controller can push to, including container registries and cluster API endpoints, inherits the compromise. Affects File Parameter Plugin 425.v3fa_801681b_5e and earlier.

Who can reach it

An authenticated Jenkins user with low privileges reaching the data binding path. No user interaction required.

What to do

Update the File Parameter Plugin past 425.v3fa_801681b_5e and restart the controller; the record does not name the fixed release. If the plugin is not in use, remove it. After patching, check the controller filesystem and plugin directory for unexpected files, since an upgrade does not remove anything already written. Short CI outage.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.