Description
Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapler data binding, allowing attackers to redirect backup writes to an attacker-specified directory and to include arbitrary files from the Jenkins controller file system in backups.
Published: 2026-09-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Jenkins ThinBackup Plugin allows an attacker to overwrite the backup configuration through Stapler data binding. By doing so, the attacker can redirect backup writes to a directory of their choice and include arbitrary files from the Jenkins controller file system in the backup. This vulnerability exposes sensitive files that may be unintentionally captured and stored in backups, potentially leading to confidentiality breaches.

Affected Systems

Jenkins Project's ThinBackup Plugin versions 2.1.4 and earlier are vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity. EPSS is not available and the issue is not listed in KEV, suggesting it may not yet have seen widespread exploitation. The attack vector is likely a web application-based data binding flaw, requiring authenticated access to the Jenkins instance. If an attacker can authenticate or manipulate the API, they can change backup destinations to arbitrary paths, causing sensitive files to be included in subsequent backups.

Generated by OpenCVE AI on September 3, 2026 at 11:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest ThinBackup Plugin version that addresses the configuration overwrite flaw.
  • Restrict backup destination directories to trusted paths and enforce appropriate file permissions.
  • Disable or limit Stapler data binding for the ThinBackup Plugin to prevent unauthorized configuration changes.

Generated by OpenCVE AI on September 3, 2026 at 11:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins Project
Jenkins Project jenkins Thinbackup Plugin
Vendors & Products Jenkins Project
Jenkins Project jenkins Thinbackup Plugin

Thu, 03 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title ThinBackup Plugin Backup Configuration Overwrite Vulnerability

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapler data binding, allowing attackers to redirect backup writes to an attacker-specified directory and to include arbitrary files from the Jenkins controller file system in backups.
References

Subscriptions

Jenkins Project Jenkins Thinbackup Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2026-09-02T17:02:07.084Z

Reserved: 2026-09-01T21:55:27.035Z

Link: CVE-2026-84667

cve-icon Vulnrichment

Updated: 2026-09-02T17:01:59.738Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T16:17:31.340

Modified: 2026-09-03T17:13:16.490

Link: CVE-2026-84667

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T16:27:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')