Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| Metrics |
cvssV3_1
|
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapler data binding, allowing attackers to redirect backup writes to an attacker-specified directory and to include arbitrary files from the Jenkins controller file system in backups. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-09-02T17:02:07.084Z
Reserved: 2026-09-01T21:55:27.035Z
Link: CVE-2026-84667
Updated: 2026-09-02T17:01:59.738Z
Status : Received
Published: 2026-09-02T16:17:31.340
Modified: 2026-09-02T18:21:33.073
Link: CVE-2026-84667
No data.
OpenCVE Enrichment
No data.
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')