CVE-2026-84676 UNKNOWN

CVE-2026-84676

Published: 2026-09-02

Description

Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…