CVE-2026-84675

high

Description

OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build.

References

https://www.jenkins.io/security/advisory/2026-09-02/#SECURITY-3987

Details

Source: Mitre, NVD

Published: 2026-09-02

Updated: 2026-09-02

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 7.4

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

Severity: High