CVE-2026-84667: Security vulnerability

Published Sep 2, 2026
·
Updated

Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapler data binding, allowing attackers to redirect backup writes to an attacker-specified directory and to include arbitrary files from the Jenkins controller file system in backups.

Affected Software

0 affected components

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Jenkins ThinBackup Plugin to a version that resolves this vulnerability.

    Fixed in 2.1.4
  2. Compensating control

    If ThinBackup Plugin versions at or below 2.1.4 are still in use, restrict access to Jenkins endpoints that could be targeted via Stapler data binding (e.g., limit who can reach/trigger ThinBackup configuration endpoints to trusted admins only) until the plugin is upgraded.

Event History

Sep 2, 2026
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
Description

Frequently Asked Questions

1

Who can exploit this issue?

An attacker who can submit requests that reach the plugin's Stapler data-binding functionality can overwrite the ThinBackup backup configuration. The provided information does not specify required Jenkins permissions or whether unauthenticated access is sufficient.

2

What impact can an attacker achieve through the altered backup configuration?

They can redirect backup writes to an attacker-specified directory and cause backups to include arbitrary files from the Jenkins controller file system.

3

Which installations are identified as affected?

Jenkins installations using ThinBackup Plugin version 2.1.4 or earlier are affected. The provided information does not state whether any particular default configuration changes exploitability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203