Description
Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration through Stapler data binding, allowing attackers to redirect history storage to an attacker-specified directory and modify history recording settings.
Published: 2026-09-02
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Jenkins Job Configuration History Plugin, in releases 1367.vc8fa_b_15101dc and earlier, contains a flaw that permits an attacker to overwrite the plugin’s history recording configuration via Stapler data binding. By sending specially crafted requests, an attacker can redirect history storage to a directory of their choice and alter settings that control how job histories are recorded. This results in unauthorized changes to the plugin’s behaviour, potentially tampering with audit logs and compromising the integrity of configuration history.

Affected Systems

The vulnerable component is the Jenkins Job Configuration History Plugin distributed by the Jenkins Project. Any Jenkins instance using a plugin version 1367.vc8fa_b_15101dc or older is impacted. No further version granularity is provided in the advisory.

Risk and Exploitability

The advisory does not publish a CVSS score, and EPSS is not available, so the exact severity and exploitation probability are not formally quantified. In the absence of an official patch, limiting write access to the plugin’s configuration files and enforcing a whitelist of allowable directories can mitigate the risk. Hardening Jenkins security by limiting exposure of Stapler endpoints and ensuring only authorized users can access the plugin configuration will reduce exploitation likelihood. The ability to redirect history storage suggests that in environments lacking stringent access controls, the potential impact on audit integrity can be significant. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 3, 2026 at 14:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Limit write permissions to the plugin’s configuration directories and enforce a directory whitelist to prevent arbitrary redirection of history storage.
  • Restrict access to Stapler data binding endpoints and apply strict authorization controls so that only trusted users can modify plugin configuration.
  • Monitor the Jenkins instance for suspicious configuration changes to the Job Configuration History Plugin and investigate anomalies promptly.

Generated by OpenCVE AI on September 3, 2026 at 14:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Configuration Modification via Stapler Data Binding in Jenkins Job Configuration History Plugin
Weaknesses CWE-20
CWE-73

Thu, 03 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Job Configuration History Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Job Configuration History Plugin

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration through Stapler data binding, allowing attackers to redirect history storage to an attacker-specified directory and modify history recording settings.
References

Subscriptions

Jenkins Project Jenkins Job Configuration History Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-02T15:40:52.114Z

Reserved: 2026-09-01T21:55:27.035Z

Link: CVE-2026-84666

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T16:17:31.247

Modified: 2026-09-03T17:13:16.490

Link: CVE-2026-84666

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T14:15:06Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-73

    External Control of File Name or Path