MEDIUMVulnerability

CVE-2026-84659

Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, allowing attackers to disable it through Stapler data binding.

Properties

severity
MEDIUM
score
4.3
cve_id
CVE-2026-84659
signal_observed_at
2026-09-23T04:35:07+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
published_at
2026-09-02T16:17:30.563
last_modified
2026-09-22T13:24:19.630

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-84659 — Ninja Signal Threat Intelligence | Ninja Signal