Junglewise Threat Intelligence

CVE-2026-84675: Jenkins TICS Plugin OS command injection via build environment variable

CVE-2026-84675 · Severity: high · CVSS 7.4 · Published 2026-09-02

Vendors: Jenkins.

Executive brief

The Jenkins TICS Plugin, used by development teams to integrate code quality analysis into build pipelines, contains an OS command injection vulnerability. An attacker who can control build environment variables can execute arbitrary commands on the build agent, potentially compromising the integrity of builds, accessing sensitive data stored on build servers, or using the compromised agent as a foothold for further attacks on the CI/CD infrastructure.

Technical details

This is an OS command injection vulnerability in Jenkins TICS Plugin version 2025.1.1 and earlier, where build environment variable values are not properly sanitized before being used in shell command construction. The vulnerability is exploitable by attackers able to control or influence build environment variables, which may be possible in multi-tenant build environments or where build parameters are derived from untrusted sources. By injecting shell metacharacters or command separators into environment variable values, an attacker can break out of the intended command and execute arbitrary OS commands with the privileges of the Jenkins agent process. Patch availability should be verified through the Jenkins security advisory and the plugin's update mechanism.

Affected products

  • Jenkins TICS Plugin 2025.1.1 and earlier

Timeline

  • 2026-09-02: disclosed: Published in Jenkins Security Advisory 2026-09-02
  • 2026-09-02: advisory

References