VYPR
Vypr IntelligenceAI-generatedSep 2, 2026· 14 CVEs

Jenkins: 14 Vulnerabilities Disclosed Together, Including High-Severity Deserialization Flaws

Jenkins Project disclosed 14 vulnerabilities on September 2, 2026, ranging from medium to high severity, impacting core components and plugins.

Key findings

  • 14 vulnerabilities disclosed simultaneously for Jenkins on September 2, 2026.
  • Multiple high-severity flaws (CVSSv3 8.8) related to insecure deserialization and Stapler component issues.
  • Stored XSS vulnerabilities found in update-center2 and the system log viewer.
  • Permission check bypasses affect build cancellation, configuration access, and agent management.
  • All vulnerabilities addressed in Jenkins core 2.580 and LTS 2.568.3.
  • Session fixation vulnerability identified due to improper session rotation.

On September 2, 2026, a significant batch of 14 vulnerabilities was disclosed for the Jenkins automation server, impacting various core components and plugins. These vulnerabilities, all disclosed simultaneously, range in severity from medium to high, with several critical flaws carrying a CVSSv3 score of 8.8. The disclosures highlight issues in areas such as cross-site scripting (XSS), improper permission checks, insecure deserialization, and session management, posing a considerable risk to Jenkins deployments.

Several vulnerabilities stem from improper handling of user-supplied data and insufficient permission checks. CVE-2026-84677, a stored XSS vulnerability in update-center2, allows attackers who can provide a plugin to inject malicious scripts into plugin metadata displayed on download index pages. Similarly, CVE-2026-84648, another stored XSS flaw, affects the system log viewer, enabling attackers controlling agent processes to inject scripts via log record metadata.

A cluster of high-severity vulnerabilities relates to deserialization flaws. CVE-2026-84650, impacting Stapler and Jenkins core, embeds user's cross-site request forgery (CSRF) tokens in dynamically generated JavaScript resources, potentially leading to CSRF attacks. CVE-2026-84645 and CVE-2026-84646, also involving Stapler and Jenkins core, allow attackers to manipulate user-submitted XML configurations, potentially leading to arbitrary code execution or unauthorized access. CVE-2026-84654 and CVE-2026-84647, again related to Stapler, permit attackers to control public static fields or instantiate arbitrary objects via form data binding, respectively. CVE-2026-84650 and CVE-2026-84649, both with CVSSv3 scores of 8.8, highlight risks associated with Stapler's handling of dynamic JavaScript and form data binding. CVE-2026-84650 specifically embeds CSRF tokens into JavaScript resources.

Other notable vulnerabilities include permission check bypasses. CVE-2026-84656 allows attackers with Overall/Manage permission to alter Appearance configuration options they should not access. CVE-2026-84653, affecting Jenkins core, permits attackers with Overall/Manage permission to modify Appearance configuration options. CVE-2026-84652 points to a session fixation vulnerability where Jenkins fails to rotate sessions upon "remember me" cookie authentication, allowing attackers to hijack sessions. CVE-2026-84651 allows attackers with Agent/Configure permission to overwrite configurations of different agents by specifying their names in submitted XML. CVE-2026-84655 involves insecure JSON and Python API responses due to unescaped map keys, allowing attackers to inject arbitrary fields. Finally, CVE-2026-84657, a medium-severity flaw, allows attackers with Item/Build permission to cancel builds initiated by other users due to a missing permission check in the build CLI command.

All disclosed vulnerabilities were addressed in Jenkins core versions 2.580 and LTS 2.568.3. Users are strongly advised to update to these patched versions to mitigate the risks associated with these numerous security flaws. The Jenkins Project's security advisory provides detailed information on each CVE and the affected versions.

This coordinated disclosure of 14 vulnerabilities underscores the importance of maintaining up-to-date Jenkins instances. The breadth of issues, from XSS to critical deserialization flaws, highlights the complex attack surface of the Jenkins ecosystem. Prompt patching is essential to protect against potential exploitation of these weaknesses.

Key Findings:

  • 14 vulnerabilities disclosed simultaneously for Jenkins on September 2, 2026.
  • Multiple high-severity flaws (CVSSv3 8.8) related to insecure deserialization and Stapler component issues.
  • Stored XSS vulnerabilities found in update-center2 and the system log viewer.
  • Permission check bypasses affect build cancellation, configuration access, and agent management.
  • All vulnerabilities addressed in Jenkins core 2.580 and LTS 2.568.3.
  • Session fixation vulnerability identified due to improper session rotation.

CVE IDs: CVE-2026-84677, CVE-2026-84657, CVE-2026-84656, CVE-2026-84655, CVE-2026-84654, CVE-2026-84653, CVE-2026-84652, CVE-2026-84651, CVE-2026-84650, CVE-2026-84649, CVE-2026-84648, CVE-2026-84647, CVE-2026-84646, CVE-2026-84645

Image Prompt: A stylized Jenkins logo made of interconnected gears and pipes, with several gears visibly cracked or emitting sparks, symbolizing the disclosed vulnerabilities. The background is a dark, abstract representation of code.

AI-written article. Grounded in 14 CVE records listed below.