SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-84645

HIGH · CVSS 8.8 EPSS 0.66% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

Jenkins versions 2.579 and earlier, as well as LTS 2.568.2 and earlier, are vulnerable due to improper handling of user-submitted `config.xml` documents, which can lead to nested field values being processed and exploited via HTTP requests. This vulnerability allows for remote code execution, posing a significant risk to the integrity and security of Jenkins instances. Organizations using affected versions should prioritize patching to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84645
Severity
HIGH
CVSS
8.8
EPSS
0.66%
Jenkins

Original NVD Description

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field values in user-submitted `config.xml` documents and subsequently handle HTTP requests via Stapler, resulting in remote code execution.

Related CVEs

Other vulnerabilities affecting the same vendor(s)