CVE-2026-84671: Jenkins File Parameter Plugin vulnerability

Published Sep 2, 2026
·
Updated

Jenkins File Parameter Plugin 425.v3fa801681b5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system through Stapler data binding, which can lead to remote code execution.

Affected Software

1 affected component
Jenkins File Parameter Plugin<=425.v3fa_801681b_5e

Event History

Sep 2, 2026
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
Description

Frequently Asked Questions

1

What access would an attacker need to exploit this issue?

The issue is reachable through Stapler data binding, but the available data does not state the required authentication level or permissions.

2

Which systems are affected?

Jenkins controllers running File Parameter Plugin version 425.v3fa_801681b_5e or earlier are affected.

3

What is the potential impact on an affected Jenkins controller?

An attacker may be able to write files to arbitrary locations on the controller file system. This can lead to remote code execution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203