SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-84646

MEDIUM · CVSS 4.3 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

Jenkins versions 2.579 and earlier, as well as LTS 2.568.2 and earlier, are vulnerable to an XML deserialization flaw that allows attackers with Overall/Read permissions to manipulate user objects by submitting specially crafted XML. This could lead to unauthorized user creation and potential escalation of privileges within the Jenkins environment. Organizations using affected versions of Jenkins should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-84646
Severity
MEDIUM
CVSS
4.3
EPSS
0.28%
Jenkins

Original NVD Description

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.

Related CVEs

Other vulnerabilities affecting the same vendor(s)