Using checksum-verified cache file /pruva/project-cache/security-3915-plugins/file-parameters.jpi Using checksum-verified cache file /pruva/project-cache/security-3915-plugins/matrix-auth.jpi Downloading pinned dependency https://updates.jenkins.io/download/plugins/ionicons-api/88.va_4187cb_eddf1/ionicons-api.hpi CONFIRMED vulnerable attempt 1: low-privilege request executed attacker Groovy after restart CONFIRMED vulnerable attempt 2: low-privilege request executed attacker Groovy after restart CONFIRMED fixed attempt 1: target path reached but incompatible class constructor did not run CONFIRMED fixed attempt 2: target path reached but incompatible class constructor did not run CVE-2026-84647 CONFIRMED: two low-privilege production HTTP attempts achieved controller code execution; two fixed controls failed closed.