CVE-2026-84655CWE-116
CVE-2026-84655
Medium · published September 2, 2026
What it is
Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API responses.
The record
Technical detail
- CVSS v3.1
- 4.3 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00192 · 8.9th percentile
- Weakness
- CWE-116 · Improper Encoding or Escaping of Output
- Published
- 2026-09-02T20:17Z
References (1)
EPSS history
Timeline