CVE-2026-84669: Path Traversal
A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permission on jobs that publish Allure report results to read arbitrary files on the Jenkins controller's file system.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs Item/Read permission on a Jenkins job that publishes Allure report results. The issue exposes files from the Jenkins controller file system.
Are all Jenkins jobs affected?
No. The affected jobs are those configured to publish Allure report results. Jobs without Allure report publishing are not identified as an exploitation path in the available information.
How can I determine whether my instance is affected?
Check whether Jenkins uses Allure Plugin version 2.35.2 or earlier, and identify jobs that publish Allure report results. Also review which users or principals have Item/Read permission on those jobs.