SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-84649

HIGH · CVSS 8.8 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Jenkins versions 2.447 to 2.579 and LTS 2.452.1 to 2.568.2 are vulnerable due to an HTTP endpoint that improperly exposes the user's CSRF token in dynamically generated JavaScript resources. This flaw allows attackers controlling a page on the same site to retrieve valid CSRF tokens, potentially enabling them to execute unauthorized actions on behalf of the user. Organizations using affected Jenkins versions should prioritize remediation to mitigate the risk of session hijacking and unauthorized actions.

CVE
CVE-2026-84649
Severity
HIGH
CVSS
8.8
EPSS
0.17%
Jenkins Java

Original NVD Description

In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resources embeds the user's cross-site request forgery (CSRF) token (crumb) as a string literal, allowing attackers with control over a page hosted on the same site as Jenkins to obtain a valid crumb for the targeted user's session and perform actions on their behalf.