SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84655

MEDIUM · CVSS 4.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Jenkins versions 2.579 and earlier, as well as LTS 2.568.2 and earlier, are vulnerable due to improper escaping of map keys during JSON and Python serialization via the REST API. This flaw allows attackers with control over map property names to inject arbitrary fields into API responses, potentially leading to data manipulation or exposure. Organizations using affected Jenkins versions should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-84655
Severity
MEDIUM
CVSS
4.3
EPSS
0.22%
Jenkins

Original NVD Description

Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API responses.

Related CVEs

Other vulnerabilities affecting the same vendor(s)