VYPR
High severity8.8NVD Advisory· Published Sep 2, 2026· Updated Sep 2, 2026

CVE-2026-84669

CVE-2026-84669

Description

A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permission on jobs that publish Allure report results to read arbitrary files on the Jenkins controller's file system.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

1