CVE-2026-84668
moderateImproper access control in Jenkins SAML Plugin allows login as any user
CVE-2026-84668 is an improper access control flaw (CWE-284) in the Jenkins SAML Plugin: through Stapler data binding, the plugin allows the stored SAML identity provider (IdP) metadata file to be overwritten, a channel reachable by low-privileged attackers (CVSS 3.1 privileges required: low). An attacker with limited access to a Jenkins controller sends a crafted request that replaces the IdP metadata with attacker-controlled content, causing Jenkins to trust SAML assertions signed by the attacker. This lets the attacker authenticate to Jenkins as any user, including administrators, with no user interaction required (CVSS 3.1: 8.8 high, with high confidentiality, integrity, and availability impact). Only Jenkins controllers using SAML Plugin version 4.618.v441a_27fa_46d2 or earlier for authentication are affected. No public proof-of-concept is known, the issue is not in CISA KEV, and EPSS assigns a 0.3% probability of exploitation in the next 30 days, so no in-the-wild exploitation is currently known.
What to do: Update the SAML Plugin to the latest release in the Jenkins update center (anything newer than 4.618.v441a_27fa_46d2). After patching, verify that the stored IdP metadata file matches your identity provider's genuine metadata and review recent sign-ins, especially administrative accounts, for anomalies, since successful exploitation leaves attackers authenticated as legitimate users. Until patched, restrict network access to the Jenkins controller and monitor authentication logs for suspicious logins.
| Jenkins (jenkinsci) SAML Plugin | all versions up to and including 4.618.v441a_27fa_46d2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled content and authenticate as any user.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.