CVE-2026-84659: Jenkins Script Security Plugin vulnerability

Published Sep 2, 2026
·
Updated

Jenkins Script Security Plugin 1412.v7737b3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, allowing attackers to disable it through Stapler data binding.

Affected Software

1 affected component
Jenkins Script Security Plugin<=1412.v7737b_3405f86

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Jenkins Script Security Plugin to a version that resolves this vulnerability.

    Fixed in 1412.v7737b_3405f86
  2. Compensating control

    Ensure the Jenkins Script Security Plugin is upgraded so that the permission check is enforced for the Stapler data binding method controlling the “Force the use of the sandbox globally in the system” setting, preventing attackers from disabling it.

Event History

Sep 2, 2026
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
Description

Frequently Asked Questions

1

What level of access does an attacker need to disable global sandbox enforcement?

The issue is exposed through Stapler data binding and affects the method controlling the global sandbox setting. The provided information does not specify the exact permissions or authentication level required.

2

Which installations are affected?

Jenkins installations using Script Security Plugin version 1412.v7737b_3405f86 or earlier are affected. The vulnerability concerns the global setting that forces use of the sandbox.

3

How can administrators determine whether they may be affected?

Check the installed Jenkins Script Security Plugin version and review whether the global “Force the use of the sandbox globally in the system” setting has been disabled. Versions 1412.v7737b_3405f86 and earlier should be treated as affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203