Loading market data...
← Back to CVE feed

CVE-2026-84659

MEDIUM CVSS 4.3 View on NVD ↗

Description

Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, allowing attackers to disable it through Stapler data binding.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Published: Sep 02, 2026 16:17 UTC Modified: Sep 02, 2026 18:21 UTC