PT-2026-84775 · Jenkins · Jenkins
CVE-2026-84652
·
Published
2026-09-02
·
Updated
2026-09-08
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins versions prior to 2.580
Jenkins LTS versions prior to 2.568.3
Description
Jenkins fails to rotate the session when a user authenticates using the "remember me" cookie. This allows an attacker capable of serving content on the same site as Jenkins to set a known session cookie in a victim's browser. Once the victim authenticates via the "remember me" cookie, the attacker gains access to Jenkins as that user.
Recommendations
Update Jenkins to version 2.580 or later.
Update Jenkins LTS to version 2.568.3 or later.
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins