Unrated severityNVD Advisory· Published Sep 2, 2026
CVE-2026-84650
CVE-2026-84650
Description
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=2.579, <=2.568.2
Patches
Vulnerability mechanics
References
1News mentions
1- Jenkins Security Advisory 2026-09-02Jenkins Security Advisories · Sep 2, 2026