SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-84650

HIGH · CVSS 8.8 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

Jenkins versions 2.579 and earlier, as well as LTS 2.568.2 and earlier, are vulnerable due to the inability to exclude transient fields from deserialization, which could allow attackers to manipulate configuration updates and potentially exploit the deserialized data. The impact of this vulnerability varies based on the usage of these transient fields within the application. Organizations using affected versions of Jenkins should prioritize this issue to mitigate potential security risks.

CVE
CVE-2026-84650
Severity
HIGH
CVSS
8.8
EPSS
0.35%
Jenkins

Original NVD Description

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used.

Related CVEs

Other vulnerabilities affecting the same vendor(s)