CVE-2026-84650CWE-502CWE-566insecure-deserialization

CVE-2026-84650

High · published September 2, 2026

CVSS v3.1
8.8
EPSS
0%
Percentile
26.4
In the wild
Unconfirmed
What it is

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used.

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00336 · 26.4th percentile
Weaknesses
CWE-502 · Deserialization of Untrusted Data; CWE-566 · Authorization Bypass Through User-Controlled SQL Primary Key
Published
2026-09-02T20:17Z
References (1)
EPSS history
Timeline
  • 04 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 02 SEP 15:40Z
    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit…
    cvelistv5