CVE-2026-84664CWE-471CWE-494

CVE-2026-84664

Medium · published September 2, 2026

CVSS v3.1
5.4
EPSS
0%
Percentile
1.0
In the wild
Unconfirmed
What it is

Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowing attackers to connect to an attacker-specified URL using GitLab API tokens already configured by administrators.

The record
Technical detail
CVSS v3.1
5.4 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00101 · 1.0th percentile
Weaknesses
CWE-471 · Modification of Assumed-Immutable Data (MAID); CWE-494 · Download of Code Without Integrity Check
Published
2026-09-02T20:17Z
References (1)
EPSS history
Timeline
  • 04 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 02 SEP 15:40Z
    Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowing attackers to…
    cvelistv5