CVE-2026-84650CWE-502CWE-566insecure-deserialization
CVE-2026-84650
High · published September 2, 2026
What it is
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used.
The record
Technical detail
- CVSS v3.1
- 8.8 · HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00336 · 26.4th percentile
- Weaknesses
- CWE-502 · Deserialization of Untrusted Data; CWE-566 · Authorization Bypass Through User-Controlled SQL Primary Key
- Published
- 2026-09-02T20:17Z
References (1)
EPSS history
Timeline
04 SEP 03:44Z
EPSS moved — → 0%
epss
02 SEP 15:40Z
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit…
cvelistv5