CVE-2026-84675EPSS p66.0%

CVE-2026-84675CVE-2026-84675

Description

OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build.

Scoring

CVSS 7.4 ()
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
EPSS1.16% probability of exploitation · percentile 66.0% · 2026-10-05T12:00:23Z
Last modified2026-09-03
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.