CVE-2026-84670: High severity Jenkins Performance Plugin vulnerability
Jenkins Performance Plugin 1015.v09ca52b3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jenkins Performance Pluginto a version that resolves this vulnerability.Fixed in 1015.v09ca_52b_3370e
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs Item/Configure permission. The impact is execution of arbitrary code on the Jenkins controller.
What data path is involved in exploitation?
The vulnerable component deserializes cached performance reports stored in the build directory on the Jenkins controller. Exploitation relies on controlling data that is deserialized through this cache path.
Are Jenkins controllers running the affected plugin versions exposed by default?
The available information identifies affected versions as Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier, but it does not state whether the vulnerable deserialization path is enabled or reachable in a default configuration.