In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used.
References
| Link | Resource |
|---|---|
| https://www.jenkins.io/security/advisory/2026-09-02/#SECURITY-4032 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-09-02 16:17
Updated : 2026-09-11 21:16
NVD link : CVE-2026-84650
Mitre link : CVE-2026-84650
CVE.ORG link : CVE-2026-84650
JSON object : View
Products Affected
jenkins
- jenkins
