CVE-2026-84671: Jenkins File Parameter Plugin vulnerability
Published Sep 2, 2026
·Updated
Jenkins File Parameter Plugin 425.v3fa801681b5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system through Stapler data binding, which can lead to remote code execution.
Affected Software
1 affected component
Jenkins File Parameter Plugin<=425.v3fa_801681b_5e
Event History
Sep 2, 2026
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
Description
Frequently Asked Questions
1
What access would an attacker need to exploit this issue?
The issue is reachable through Stapler data binding, but the available data does not state the required authentication level or permissions.
2
Which systems are affected?
Jenkins controllers running File Parameter Plugin version 425.v3fa_801681b_5e or earlier are affected.
3
What is the potential impact on an affected Jenkins controller?
An attacker may be able to write files to arbitrary locations on the controller file system. This can lead to remote code execution.