CVE-2026-84652CWE-384

CVE-2026-84652

High · published September 2, 2026

CVSS v3.1
7.3
EPSS
0%
Percentile
29.3
In the wild
Unconfirmed
What it is

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known session cookie in the victim's browser, which after the victim authenticates via the "remember me" cookie, grants the attacker access to Jenkins as that user.

The record
Technical detail
CVSS v3.1
7.3 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00362 · 29.3th percentile
Weakness
CWE-384 · Session Fixation
Published
2026-09-02T20:17Z
References (1)
EPSS history
Timeline
  • 04 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 02 SEP 15:40Z
    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing…
    cvelistv5