SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-84653

LOW · CVSS 3.5 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Jenkins versions 2.421 to 2.579 and LTS 2.426.1 to 2.568.2 have a vulnerability that fails to enforce proper permission checks on the Appearance configuration page. This allows users with Overall/Manage permissions to alter configuration settings beyond their intended access, potentially leading to unauthorized changes in the Jenkins interface. Organizations using these versions of Jenkins should prioritize remediation to prevent misuse of appearance settings by unauthorized users.

CVE
CVE-2026-84653
Severity
LOW
CVSS
3.5
EPSS
0.18%
Jenkins

Original NVD Description

Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.