PatchSiren cyber security CVE debrief
CVE-2016-4986 Jenkins CVE debrief
CVE-2016-4986 is a high-severity directory traversal issue in the Jenkins TAP plugin. According to NVD, versions before 1.25 are vulnerable and a remote attacker can read arbitrary files through an unspecified parameter. The weakness is categorized as CWE-22, and the CVSS v3.1 vector indicates network access, no privileges, no user interaction, and high confidentiality impact.
- Vendor
- Jenkins
- Product
- Tap
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-09
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-09
- Advisory updated
- 2026-05-13
Who should care
Jenkins administrators and operators who have the TAP plugin installed, especially on internet-reachable or broadly accessible Jenkins instances. Security teams should also prioritize this if Jenkins is used in build pipelines that may expose sensitive source code, credentials, or configuration files.
Technical summary
NVD describes the flaw as a directory traversal vulnerability in the TAP plugin before version 1.25. The attack surface is remote and requires no authentication or user interaction. The reported impact is confidentiality-only: an attacker may be able to read arbitrary files via an unspecified parameter. NVD maps the weakness to CWE-22 and assigns CVSS 3.1 vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N.
Defensive priority
High. The issue is remotely reachable, requires no privileges, and can expose sensitive files. If the TAP plugin is installed, it should be treated as an urgent patching and exposure-review item.
Recommended defensive actions
- Check whether the Jenkins TAP plugin is installed on any Jenkins controller or shared environment.
- Upgrade the TAP plugin to version 1.25 or later, as NVD marks versions before 1.25 as vulnerable.
- If immediate upgrading is not possible, reduce exposure to Jenkins and restrict access to trusted networks and users.
- Review Jenkins logs and surrounding file-access telemetry for signs of unusual requests against the TAP plugin.
- Assess whether sensitive files accessible to the Jenkins process could be exposed and rotate any credentials that may have been readable.
Evidence notes
The NVD record states that the vulnerable component is the Jenkins TAP plugin before 1.25 and describes remote arbitrary file read via directory traversal. NVD also lists CWE-22 and the CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. The vendor advisory referenced by NVD is the Jenkins Security Advisory 2016-06-20.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-4986 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-4986
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-4986 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-4986
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-06-20
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.