CVE-2026-84676CWE-311
CVE-2026-84676
Medium · published September 2, 2026
What it is
Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
The record
Technical detail
- CVSS v3.1
- 4.3 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00120 · 2.0th percentile
- Weakness
- CWE-311 · Missing Encryption of Sensitive Data
- Published
- 2026-09-02T20:17Z
References (1)
EPSS history
Timeline