PT-2026-84768 · Jenkins · Jenkins

CVE-2026-84645

·

Published

2026-09-02

·

Updated

2026-09-08

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins versions prior to 2.580 Jenkins LTS versions prior to 2.568.3
Description Objects that store their configuration in independent top-level configuration files, such as jobs and global configuration, can be smuggled as nested field values within user-submitted config.xml documents. This allows these objects to handle HTTP requests via Stapler, a web framework used by Jenkins to map URLs to Java objects. An attacker capable of submitting or modifying the config.xml file can trigger unsafe request routing to reach code paths that lead to remote code execution.
Recommendations Update Jenkins to version 2.580 or later. Update Jenkins LTS to version 2.568.3 or later.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-JENKINS-2026-84645
CVE-2026-84645

Affected Products

Jenkins