PatchSiren cyber security CVE debrief
CVE-2026-84666 Jenkins Project CVE debrief
The CVE record for CVE-2026-84666 was published on 2026-09-02T16:17:31.247Z. This vulnerability affects Jenkins Job Configuration History Plugin version 1367.vc8fa_b_15101dc and earlier. The vulnerability allows attackers to redirect history storage to an attacker-specified directory and modify history recording settings through Stapler data binding. This issue has a medium severity and requires attention from Jenkins administrators and users to prevent potential configuration history tampering. The CVE record has not been modified since its publication.
- Vendor
- Jenkins Project
- Product
- Jenkins Job Configuration History Plugin
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-02
- Original CVE updated
- 2026-09-04
- Advisory published
- 2026-09-02
- Advisory updated
- 2026-09-04
Who should care
Jenkins administrators, security teams, and developers using Jenkins Job Configuration History Plugin, particularly those with medium-severity concerns, should review and update the plugin to prevent potential configuration history tampering and ensure the security of their Jenkins environments.
Technical summary
Jenkins Job Configuration History Plugin version 1367.vc8fa_b_15101dc and earlier is vulnerable to a configuration history tampering issue. The plugin allows overwriting of its history recording configuration through Stapler data binding, enabling attackers to redirect history storage to an attacker-specified directory and modify history recording settings. This vulnerability impacts Jenkins administrators and users, potentially allowing unauthorized configuration changes and history modifications. To mitigate this issue, it is recommended to review and update the plugin to a version beyond 1367.vc8fa_b_15101dc, restrict access to Stapler data binding, and monitor plugin's history recording configuration and storage for suspicious activity.
Defensive priority
Medium-severity vulnerability in Jenkins Job Configuration History Plugin, requiring prompt attention to prevent potential configuration history tampering.
Recommended defensive actions
- Review and update Jenkins Job Configuration History Plugin to version beyond 1367.vc8fa_b_15101dc
- Restrict access to Stapler data binding to prevent unauthorized configuration changes
- Monitor plugin's history recording configuration and storage for suspicious activity
- Implement compensating controls to detect and prevent potential configuration tampering
- Conduct a thorough review of Jenkins Job Configuration History Plugin settings and history
- Verify plugin configuration and history recording settings are properly secured
- Track and analyze plugin updates and patches for potential security enhancements
Evidence notes
Evidence from official CVE Program record and NIST NVD detail page indicates vulnerability in Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier, allowing attackers to redirect history storage and modify history recording settings via Stapler data binding. Limited source detail suggests verifying plugin version, reviewing configuration history, and monitoring for suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-84666 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-84666
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-84666 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84666
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.jenkins.io/security/advisory/2026-09-02/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.