Executive brief
Jenkins Allure Plugin is used to publish and display test report results in Jenkins CI/CD environments. A path traversal vulnerability allows authenticated users with read access to specific jobs to read arbitrary files from the Jenkins controller's filesystem, potentially exposing sensitive credentials, configuration data, and other private files stored on the server.
Technical details
A path traversal vulnerability exists in Jenkins Allure Plugin versions 2.35.2 and earlier that allows attackers with Item/Read permission on jobs that publish Allure reports to access arbitrary files on the Jenkins controller filesystem. The vulnerability is in the report retrieval mechanism, where insufficient path validation permits traversal sequences (e.g., "../") to escape the intended report directory. The attack requires authentication and knowledge of at least one job configured to publish Allure reports. Successful exploitation results in unauthorized information disclosure of sensitive files stored on the Jenkins master node. The vulnerability has been assigned CVE-2026-84669 and patched in versions after 2.35.2.
Affected products
- Jenkins Allure Plugin 2.35.2 and earlier
Timeline
- 2026-09-02: disclosed