CVE-2026-84650

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*

History

No history.

Information

Published : 2026-09-02 16:17

Updated : 2026-09-11 21:16


NVD link : CVE-2026-84650

Mitre link : CVE-2026-84650

CVE.ORG link : CVE-2026-84650


JSON object : View

Products Affected

jenkins

  • jenkins
CWE
CWE-502

Deserialization of Untrusted Data

CWE-566

Authorization Bypass Through User-Controlled SQL Primary Key