CVE-2026-84658
Summary
| CVE | CVE-2026-84658 |
| State | PUBLISHED |
| Assigner | jenkins |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-02 16:17:30 UTC |
| Updated | 2026-09-02 16:17:30 UTC |
| Description | Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowing attackers able to submit certain forms to read that configuration. |
Vendor Declared Affected Products
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.