CVE-2026-84668

Summary

Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled content and authenticate as any user.

Affected Software

VendorProductVersion RangeStatus
Jenkins ProjectJenkins SAML Plugin0 <= 4.618.v441a_27fa_46d2affected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References