CVE-2026-84670

8.8

Jenkins · Jenkins Performance Plugin

The Jenkins Performance Plugin contains a deserialization vulnerability allowing authenticated users with Item/Configure permission to execute arbitrary code on the Jenkins controller.

Executive summary

A critical deserialization vulnerability in the Jenkins Performance Plugin allows attackers with configured permissions to execute arbitrary code on the Jenkins controller.

Vulnerability

The plugin fails to restrict the classes that can be instantiated during the deserialization of cached performance reports. An attacker with Item/Configure permission can exploit this to trigger arbitrary code execution on the Jenkins controller.

Business impact

Given the CVSS score of 8.8, this vulnerability poses a severe threat to Jenkins infrastructure. Successful exploitation allows for complete control over the controller, enabling attackers to compromise build processes, access sensitive environment variables, and potentially move laterally into the production environment.

Remediation

Immediate Action: Update the Jenkins Performance Plugin to a version greater than 1015.v09ca_52b_3370e.

Proactive Monitoring: Review Jenkins logs for unauthorized modifications to build configurations or suspicious performance report activity.

Compensating Controls: Audit and restrict user permissions within the Jenkins environment to ensure that only authorized personnel have the Item/Configure capability.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The vulnerability requires immediate attention to prevent potential system compromise. Administrators must prioritize updating the Performance Plugin to the latest version to mitigate the risk of arbitrary code execution.

More Jenkins CVEs

Sources