SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84654

MEDIUM · CVSS 5.4 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Jenkins versions 2.579 and earlier, along with LTS 2.568.2 and earlier, are vulnerable due to a flaw in the Stapler framework that permits unauthorized modification of public static fields in configuration objects through form data binding. This could allow attackers with access to submit configuration forms to make global changes to the Jenkins instance, potentially leading to significant security risks. Organizations using affected Jenkins versions should prioritize remediation to mitigate the risk of unauthorized configuration manipulation.

CVE
CVE-2026-84654
Severity
MEDIUM
CVSS
5.4
EPSS
0.20%
Jenkins

Original NVD Description

In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, form data binding allows setting public static fields of the bound configuration object, allowing attackers who can submit configuration forms to modify public static fields of the configuration objects those forms are bound to, resulting in changes that apply globally to the Jenkins instance.