PT-2026-84768 · Jenkins · Jenkins
CVE-2026-84645
·
Published
2026-09-02
·
Updated
2026-09-08
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jenkins versions prior to 2.580
Jenkins LTS versions prior to 2.568.3
Description
Objects that store their configuration in independent top-level configuration files, such as jobs and global configuration, can be smuggled as nested field values within user-submitted
config.xml documents. This allows these objects to handle HTTP requests via Stapler, a web framework used by Jenkins to map URLs to Java objects. An attacker capable of submitting or modifying the config.xml file can trigger unsafe request routing to reach code paths that lead to remote code execution.Recommendations
Update Jenkins to version 2.580 or later.
Update Jenkins LTS to version 2.568.3 or later.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins