PT-2026-84775 · Jenkins · Jenkins

CVE-2026-84652

·

Published

2026-09-02

·

Updated

2026-09-08

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Jenkins versions prior to 2.580 Jenkins LTS versions prior to 2.568.3
Description Jenkins fails to rotate the session when a user authenticates using the "remember me" cookie. This allows an attacker capable of serving content on the same site as Jenkins to set a known session cookie in a victim's browser. Once the victim authenticates via the "remember me" cookie, the attacker gains access to Jenkins as that user.
Recommendations Update Jenkins to version 2.580 or later. Update Jenkins LTS to version 2.568.3 or later.

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-JENKINS-2026-84652
CVE-2026-84652

Affected Products

Jenkins