SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-84647

HIGH · CVSS 8.8 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Jenkins versions 2.579 and earlier, as well as LTS 2.568.2 and earlier, are vulnerable due to Stapler's failure to restrict object instantiation through form data binding, potentially allowing attackers with Overall/Read permissions to manipulate configuration-related objects improperly. This vulnerability could lead to unauthorized changes in system configuration, posing a risk to the integrity and security of Jenkins environments. Organizations using affected versions of Jenkins should prioritize remediation to mitigate potential exploitation risks.

CVE
CVE-2026-84647
Severity
HIGH
CVSS
8.8
EPSS
0.43%
Jenkins

Original NVD Description

In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field type, allowing attackers with Overall/Read permission to instantiate types related to configuration for which that field type was not intended.