CVE-2026-84659: Jenkins Script Security Plugin vulnerability
Jenkins Script Security Plugin 1412.v7737b3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, allowing attackers to disable it through Stapler data binding.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jenkins Script Security Pluginto a version that resolves this vulnerability.Fixed in 1412.v7737b_3405f86 - Compensating control
Ensure the Jenkins Script Security Plugin is upgraded so that the permission check is enforced for the Stapler data binding method controlling the “Force the use of the sandbox globally in the system” setting, preventing attackers from disabling it.
Event History
Frequently Asked Questions
What level of access does an attacker need to disable global sandbox enforcement?
The issue is exposed through Stapler data binding and affects the method controlling the global sandbox setting. The provided information does not specify the exact permissions or authentication level required.
Which installations are affected?
Jenkins installations using Script Security Plugin version 1412.v7737b_3405f86 or earlier are affected. The vulnerability concerns the global setting that forces use of the sandbox.
How can administrators determine whether they may be affected?
Check the installed Jenkins Script Security Plugin version and review whether the global “Force the use of the sandbox globally in the system” setting has been disabled. Versions 1412.v7737b_3405f86 and earlier should be treated as affected.