Jenkins SAML Plugin <=4.618: Metadata file overwrite via Stapler
CVE-2026-84668 Published on September 2, 2026
Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled content and authenticate as any user.
Vulnerability Analysis
CVE-2026-84668 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
What is an Authorization Vulnerability?
The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVE-2026-84668 has been classified to as an Authorization vulnerability or weakness.
Products Associated with CVE-2026-84668
Want to know whenever a new CVE is published for Jenkins? stack.watch will email you.
Affected Versions
Jenkins Project Jenkins SAML Plugin:- Before and including 4.618.v441a_27fa_46d2 is affected.