CVE-2026-84668: Jenkins Jenkins SAML Plugin vulnerability
Published Sep 2, 2026
·Updated
Jenkins SAML Plugin 4.618.v441a27fa46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled content and authenticate as any user.
Affected Software
1 affected component
Jenkins Jenkins SAML Plugin<=4.618.v441a_27fa_46d2
Event History
Sep 2, 2026
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
Description
Data Sourced
via NVD·04:17 PM
Description
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must be able to use the affected plugin’s Stapler data-binding functionality to overwrite the SAML identity provider metadata file. The provided information does not state whether prior Jenkins authentication or administrative permissions are required.
2
What is the impact if exploitation succeeds?
An attacker can replace the SAML identity provider metadata with attacker-controlled content and then authenticate as any user.
3
Which plugin versions are affected?
Jenkins SAML Plugin versions 4.618.v441a_27fa_46d2 and earlier are affected.