ZeroHour

CVE-2026-84668

moderate

Improper access control in Jenkins SAML Plugin allows login as any user

CVSS 3.1
8.8 high
EPSS
<1%p18
Published
()
Modified
AI analysis

CVE-2026-84668 is an improper access control flaw (CWE-284) in the Jenkins SAML Plugin: through Stapler data binding, the plugin allows the stored SAML identity provider (IdP) metadata file to be overwritten, a channel reachable by low-privileged attackers (CVSS 3.1 privileges required: low). An attacker with limited access to a Jenkins controller sends a crafted request that replaces the IdP metadata with attacker-controlled content, causing Jenkins to trust SAML assertions signed by the attacker. This lets the attacker authenticate to Jenkins as any user, including administrators, with no user interaction required (CVSS 3.1: 8.8 high, with high confidentiality, integrity, and availability impact). Only Jenkins controllers using SAML Plugin version 4.618.v441a_27fa_46d2 or earlier for authentication are affected. No public proof-of-concept is known, the issue is not in CISA KEV, and EPSS assigns a 0.3% probability of exploitation in the next 30 days, so no in-the-wild exploitation is currently known.

What to do: Update the SAML Plugin to the latest release in the Jenkins update center (anything newer than 4.618.v441a_27fa_46d2). After patching, verify that the stored IdP metadata file matches your identity provider's genuine metadata and review recent sign-ins, especially administrative accounts, for anomalies, since successful exploitation leaves attackers authenticated as legitimate users. Until patched, restrict network access to the Jenkins controller and monitor authentication logs for suspicious logins.

Affected
Jenkins (jenkinsci) SAML Pluginall versions up to and including 4.618.v441a_27fa_46d2
Estimated exposure
moderatetens of thousands of Jenkins instances (order of 20,000-30,000 active installs of the SAML Plugin) — Jenkins plugin telemetry has historically shown the SAML Plugin with tens of thousands of active installs, and only controllers that use SAML for single sign-on on a version at or below 4.618.v441a_27fa_46d2 are affected; this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled content and authenticate as any user.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.