CVE-2026-84676
EUVD-2026-7014902.09.2026, 16:17
Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| jenkins | parameterized_remote_trigger | 𝑥 ≤ 3.2.2 | CNA |
Common Weakness Enumeration