SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-84652

HIGH · CVSS 7.3 EPSS 0.47%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

Jenkins versions 2.579 and earlier, as well as LTS 2.568.2 and earlier, are vulnerable due to improper session management when users authenticate using the "remember me" cookie. This flaw allows attackers to exploit the session by setting a known cookie in the victim's browser, potentially granting them unauthorized access to Jenkins as the authenticated user. Organizations using these versions of Jenkins should prioritize this issue to mitigate the risk of session hijacking attacks.

CVE
CVE-2026-84652
Severity
HIGH
CVSS
7.3
EPSS
0.47%
Jenkins

Original NVD Description

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known session cookie in the victim's browser, which after the victim authenticates via the "remember me" cookie, grants the attacker access to Jenkins as that user.

Related CVEs

Other vulnerabilities affecting the same vendor(s)