CVE-2026-84671
moderatePath Traversal in Jenkins File Parameter Plugin Enables Controller RCE
Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier contains a path traversal flaw (CWE-22): Stapler data binding does not constrain where submitted file parameter data is written, so files can be written to arbitrary locations on the Jenkins controller's file system. The flaw is triggered over the network when an authenticated user with limited privileges (the CVSS 3.1 vector requires PR:L) submits crafted input through the plugin's data binding, with no user interaction required. Because an arbitrary file write on the controller can overwrite files the controller executes or relies on, it can be escalated to full remote code execution with high impact on confidentiality, integrity, and availability. Only Jenkins controllers with the File Parameter Plugin at version 425.v3fa_801681b_5e or earlier are affected; Jenkins core and other plugins are not implicated. There is no known public proof-of-concept or exploitation, EPSS estimates only a 0.6% probability of exploitation within 30 days, and the issue is not in CISA's KEV catalog.
What to do: Update the File Parameter Plugin to the first release newer than 425.v3fa_801681b_5e via the Jenkins update center; no fixed version number is specified in the available data. Until patched, restrict which authenticated users can trigger builds or requests that reach this plugin's data binding, and review the controller's file system and logs for unexpected files written outside expected directories as signs of compromise. If the plugin is installed but unused, consider disabling it.
| Jenkins File Parameter Plugin | 425.v3fa_801681b_5e and earlier (all versions through 425.v3fa_801681b_5e) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system through Stapler data binding, which can lead to remote code execution.
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.