🚨 CVE-2026-84676
Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
🎖@cveNotify

Jenkins Security Advisory 2026-09-02
Jenkins – an open source automation server which enables developers around the world to reliably build, test, and deploy their software
September 2, 2026 25