PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-84666 Jenkins Project CVE debrief

The CVE record for CVE-2026-84666 was published on 2026-09-02T16:17:31.247Z. This vulnerability affects Jenkins Job Configuration History Plugin version 1367.vc8fa_b_15101dc and earlier. The vulnerability allows attackers to redirect history storage to an attacker-specified directory and modify history recording settings through Stapler data binding. This issue has a medium severity and requires attention from Jenkins administrators and users to prevent potential configuration history tampering. The CVE record has not been modified since its publication.

Vendor
Jenkins Project
Product
Jenkins Job Configuration History Plugin
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-02
Original CVE updated
2026-09-04
Advisory published
2026-09-02
Advisory updated
2026-09-04

Who should care

Jenkins administrators, security teams, and developers using Jenkins Job Configuration History Plugin, particularly those with medium-severity concerns, should review and update the plugin to prevent potential configuration history tampering and ensure the security of their Jenkins environments.

Technical summary

Jenkins Job Configuration History Plugin version 1367.vc8fa_b_15101dc and earlier is vulnerable to a configuration history tampering issue. The plugin allows overwriting of its history recording configuration through Stapler data binding, enabling attackers to redirect history storage to an attacker-specified directory and modify history recording settings. This vulnerability impacts Jenkins administrators and users, potentially allowing unauthorized configuration changes and history modifications. To mitigate this issue, it is recommended to review and update the plugin to a version beyond 1367.vc8fa_b_15101dc, restrict access to Stapler data binding, and monitor plugin's history recording configuration and storage for suspicious activity.

Defensive priority

Medium-severity vulnerability in Jenkins Job Configuration History Plugin, requiring prompt attention to prevent potential configuration history tampering.

Recommended defensive actions

  • Review and update Jenkins Job Configuration History Plugin to version beyond 1367.vc8fa_b_15101dc
  • Restrict access to Stapler data binding to prevent unauthorized configuration changes
  • Monitor plugin's history recording configuration and storage for suspicious activity
  • Implement compensating controls to detect and prevent potential configuration tampering
  • Conduct a thorough review of Jenkins Job Configuration History Plugin settings and history
  • Verify plugin configuration and history recording settings are properly secured
  • Track and analyze plugin updates and patches for potential security enhancements

Evidence notes

Evidence from official CVE Program record and NIST NVD detail page indicates vulnerability in Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier, allowing attackers to redirect history storage and modify history recording settings via Stapler data binding. Limited source detail suggests verifying plugin version, reviewing configuration history, and monitoring for suspicious activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-84666 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-84666

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-84666 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84666

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.