Loading market data...
← Back to CVE feed

CVE-2026-84667

HIGH CVSS 7.1 View on NVD ↗

Description

Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapler data binding, allowing attackers to redirect backup writes to an attacker-specified directory and to include arbitrary files from the Jenkins controller file system in backups.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Published: Sep 02, 2026 16:17 UTC Modified: Sep 02, 2026 18:21 UTC